CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-65118

CVSS 9.3v4.0pub. 2026-01-16upd. 2026-01-22

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.

🤖 AI Analysis
How it works

The vulnerability results from an uncontrolled library or component search path (CWE-427, uncontrolled search path element). An attacker with standard system privileges can plant a malicious library or executable file in a location searched by Process Optimization services during startup or operation. The service loads the substituted code in the context of a highly privileged OS System account, leading to privilege escalation.

Impact

An attacker can obtain OS System privileges and completely compromise the Model Application Server, gaining full control over processed process data and OT infrastructure.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references (AVEVA support portal: https://softwaresupportsp.aveva.com and security updates page https://www.aveva.com/en/support-and-success/cyber-security-updates/). It is also recommended to restrict local access to systems with installed software only to trusted users and to monitor library search directories for unauthorized modifications.

Who is affected

Aveva Process Optimization — versions specified in vendor references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Aveva Process Optimization

    APP
    Aveva
    < 2025
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2025-61937CRITICAL10.0PL ✓same product

RCE z uprawnieniami systemowymi w Aveva Process Optimization

CVE-2025-61943CRITICAL9.3PL ✓same product

SQL Injection w Aveva Process Optimization umożliwiający RCE

CVE-2025-64691CRITICAL9.3PL ✓same product

Privilege escalation przez manipulację skryptami TCL w Aveva Process Optimization

CVE-2025-64729HIGH8.6same product

The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to tamper with Pro...

CVE-2025-64769HIGH7.6same product

The Process Optimization application suite leverages connection channels/protocols that by-default are not en...