CVE-2025-64729

8.1

AVEVA · Process Optimization

An authenticated OS standard user can tamper with Process Optimization project files to embed malicious code, leading to privilege escalation when a victim user interacts with the project files.

Executive summary

A vulnerability in AVEVA Process Optimization allows authenticated users to achieve privilege escalation via malicious project file tampering, posing a significant risk of unauthorized access.

Vulnerability

This flaw, classified as CWE-862 (Missing Authorization), allows an authenticated user with standard OS privileges to modify project files. By injecting malicious code into these files, an attacker can escalate privileges when an unsuspecting victim user opens or interacts with the compromised project.

Business impact

The ability for a standard user to escalate privileges represents a critical security failure, potentially granting an attacker full control over the application or the victim's session. With a CVSS score of 8.1, this high-severity vulnerability could lead to significant data compromise, unauthorized lateral movement within the production environment, and potential operational disruption.

Remediation

Immediate Action: Update all instances of AVEVA Process Optimization to version 2025 or later as specified in the vendor security bulletin AVEVA-2026-001.

Proactive Monitoring: Review access logs for unusual modifications to project file directories and monitor for suspicious process execution patterns initiated by standard user accounts.

Compensating Controls: Implement strict file system permissions to limit write access to project directories and enforce the principle of least privilege for all OS user accounts interacting with the software.

Exploitation status

Public Exploit Available: No — exploit_available is false.

Analyst recommendation

Given the potential for privilege escalation and the availability of a vendor-provided patch, organizations must prioritize upgrading to version 2025 immediately. Failure to address this vulnerability increases the risk of internal actors or compromised accounts gaining unauthorized administrative control over critical process optimization workflows.

Sources

Originally found and disclosed by Christopher Wu of Veracode reported these vulnerabilities to AVEVA., per the CVE Program record.