Privilege‑Escalation Vulnerability (CVE‑2026‑77477) in OPCFoundation OPC UA LocalDiscoveryServer Threatens High‑Privilege Terminals
What It Is — The OPCFoundation OPC UA LocalDiscoveryServer (LDS) installer contains a flaw (CVE‑2026‑77477) that lets an attacker who can launch the installer with elevated rights intercept the high‑privilege console window and execute arbitrary commands.
Exploitability — No public exploit code is known, but the vulnerability is exploitable locally during installation when an attacker has physical access to the keyboard/display and can run the installer with admin rights. CVSS v3 base score 4.6 (Low).
Affected Products — OPCFoundation OPC UA LocalDiscoveryServer (LDS) installers < 1.04.420.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for privileged‑access controls and strict “least‑privilege” enforcement during software deployment – a control objective that maps to many frameworks (e.g., NIST CSF 2.0).
- Continuous monitoring of installer activity and audit‑ready evidence of privileged‑session isolation are now expected by auditors and enterprise buyers.
- A single control lapse can cascade into a breach of critical‑infrastructure OT environments, eroding the trust signal you provide to partners and regulators.
Recommended Actions
- Update all OPC UA LDS installers to version 1.04.420 or later.
- Enforce policy that only authorized, audited service‑account credentials may run installer binaries; log all privileged installer executions.
- Deploy endpoint controls that block console‑window capture tools during high‑privilege installations.
Source: CISA Advisory – ICSA‑26‑246‑01