top of page
perceptive_background_267k.jpg

The vulnerability, if exploited, could allow an authenticated miscreant
(OS Standard User) to trick Process Optimization services into loading
arbitrary code …

Published:

15 januari 2026 om 23:00:00

Alert date:

16 januari 2026 om 03:02:30

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Enterprise Applications

CVE-2025-65118 is a privilege escalation vulnerability in AVEVA Process Optimization services. An authenticated OS Standard User can exploit this vulnerability to trick the Process Optimization services into loading arbitrary code. Successful exploitation allows privilege escalation to OS System level, potentially resulting in complete compromise of the Model Application Server. The vulnerability affects AVEVA industrial control systems and poses significant risk to operational technology environments.

Technical details

Mitigation steps:

Affected products:

AVEVA Process Optimization
Model Application Server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page