CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-64691

CVSS 9.3v4.0pub. 2026-01-16upd. 2026-01-22

The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially resulting in complete compromise of the model application server.

🤖 AI Analysis
How it works

The vulnerability classified as CWE-94 (Code Injection) allows an authenticated but unprivileged operating system user to modify TCL Macro scripts in the application. The manipulated scripts are then executed in the context of higher privileges, leading to privilege escalation from the level of an ordinary OS user to system level (OS system). The attack vector is local, does not require user interaction or special preconditions beyond having a standard OS account.

Impact

An attacker can obtain system privileges on the host, resulting in complete takeover of the model application server, including full control over data, configuration, and industrial processes handled by the application.

Mitigation & patch

Apply patches available from the vendor according to references (Aveva support portal: softwaresupportsp.aveva.com and security updates page aveva.com). It is also recommended to restrict local system access exclusively to trusted, necessary user accounts and to monitor changes in TCL Macro scripts.

Who is affected

Aveva Process Optimization — versions indicated in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Aveva Process Optimization

    APP
    Aveva
    < 2025
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2025-61937CRITICAL10.0PL ✓same product

RCE z uprawnieniami systemowymi w Aveva Process Optimization

CVE-2025-61943CRITICAL9.3PL ✓same product

SQL Injection w Aveva Process Optimization umożliwiający RCE

CVE-2025-65118CRITICAL9.3PL ✓same product

Privilege escalation w Aveva Process Optimization (CWE-427)

CVE-2025-64729HIGH8.6same product

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Pro...

CVE-2025-64769HIGH7.6same product

The Process Optimization application suite leverages connection channels/protocols that by-default are not en...