CVE-2025-64691

8.8

AVEVA · Process Optimization

An authenticated local user can tamper with TCL Macro scripts in AVEVA Process Optimization, leading to OS-level privilege escalation and complete system compromise.

Executive summary

A high-severity privilege escalation vulnerability in AVEVA Process Optimization allows authenticated standard users to achieve full system control.

Vulnerability

This vulnerability, classified as CWE-94 (Code Injection), occurs when a local authenticated user manipulates TCL Macro scripts to execute arbitrary code with elevated system privileges. The attack vector requires low-level user access to the local machine to trigger the escalation.

Business impact

The ability for a standard user to escalate privileges to the operating system level presents a significant risk to operational integrity and data confidentiality. Given the CVSS score of 8.8, this vulnerability could result in a full compromise of the application server, potentially allowing unauthorized actors to disrupt critical industrial processes or access sensitive production data.

Remediation

Immediate Action: Update the affected software to AVEVA Process Optimization version 2025 as instructed in the vendor security bulletin AVEVA-2026-001.

Proactive Monitoring: Review system logs for unauthorized attempts to modify TCL scripts or unexpected execution of administrative processes by non-privileged accounts.

Compensating Controls: Implement strict file integrity monitoring on the directory paths housing TCL Macro scripts to detect unauthorized modifications.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing AVEVA Process Optimization must prioritize the upgrade to version 2025 to eliminate this privilege escalation path. Failure to patch allows any authenticated user on the host system to gain full administrative control, which poses an unacceptable risk to infrastructure security.

Sources

Originally found and disclosed by Christopher Wu of Veracode reported these vulnerabilities to AVEVA., per the CVE Program record.