


Perceptive Security
SOC/SIEM Consultancy

The vulnerability, if exploited, could allow an authenticated miscreant
(Process Optimization Designer User) to embed OLE objects into graphics,
and escalate …
Published:
15 januari 2026 om 23:00:00
Alert date:
16 januari 2026 om 17:05:17
Source:
nvd.nist.gov
Critical Infrastructure, Enterprise Applications
CVE-2025-65117 is a privilege escalation vulnerability affecting AVEVA's Process Optimization Designer. An authenticated user with Process Optimization Designer User privileges can exploit this vulnerability by embedding malicious OLE objects into graphics. When a victim user interacts with these compromised graphical elements, the attacker can escalate their privileges to the identity of the victim user. This vulnerability requires initial authentication but allows for horizontal privilege escalation through social engineering via embedded graphics objects.
Technical details
Mitigation steps:
Affected products:
AVEVA Process Optimization Designer
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-65117
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json
https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea
https://www.aveva.com/en/support-and-success/cyber-security-updates/
https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
