top of page
perceptive_background_267k.jpg

The vulnerability, if exploited, could allow an authenticated miscreant
(OS standard user) to tamper with TCL Macro scripts and escalate
privileges to OS syst…

Published:

15 januari 2026 om 23:00:00

Alert date:

16 januari 2026 om 16:17:23

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Enterprise Applications

CVE-2025-64691 is a privilege escalation vulnerability affecting AVEVA software that allows authenticated OS standard users to tamper with TCL Macro scripts. Successful exploitation enables privilege escalation to OS system level, potentially resulting in complete compromise of the model application server. The vulnerability affects industrial control systems and requires authentication but can lead to full system compromise. CISA has issued an advisory (ICSA-26-015-01) regarding this vulnerability. The issue impacts AVEVA's industrial software solutions used in operational technology environments.

Technical details

Mitigation steps:

Affected products:

AVEVA

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page