CVE-2025-30033
7.8Siemens · Automation License Manager, CEMAT, CP PtP Param, Create MyConfig, Energy Support Library
Multiple Siemens software products contain a DLL hijacking vulnerability in their setup component, which may allow an attacker to execute arbitrary code during the installation process.
Executive summary
A DLL hijacking vulnerability in multiple Siemens products exposes systems to arbitrary code execution if a user runs a malicious installer component.
Vulnerability
The vulnerability is an uncontrolled search path element (CWE-427) within the setup component. It allows an unauthenticated attacker to achieve arbitrary code execution by tricking a user into executing an installation process that loads a malicious library.
Business impact
The vulnerability carries a CVSS score of 7.8, indicating a high risk to system integrity and availability. Successful exploitation allows an attacker to execute code with the privileges of the user running the installer, potentially leading to full system compromise, the installation of malware, or unauthorized access to sensitive operational technology environments.
Remediation
Immediate Action: Review the official Siemens security advisory at the provided reference link to identify specific update paths for your installed software versions and apply available security patches immediately.
Proactive Monitoring: Monitor system logs for unexpected file creation or library loading events during software installation processes, specifically looking for unauthorized DLLs in application directories.
Compensating Controls: Ensure that installers are executed from secure, read-only network locations and that users are instructed to verify the integrity and source of all software installation packages before execution.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability presents a high risk due to the potential for arbitrary code execution on systems running Siemens software. Organizations should prioritize identifying affected installations across their infrastructure and applying vendor-supplied updates as soon as they become available. Until patches are applied, restrict administrative privileges and enforce strict software deployment policies to minimize the potential for exploitation.