CVE-2025-65118

8.8

AVEVA · Process Optimization

An authenticated OS standard user can exploit a DLL hijacking vulnerability in AVEVA Process Optimization to achieve local privilege escalation to OS System.

Executive summary

A vulnerability in AVEVA Process Optimization allows authenticated standard users to execute arbitrary code with system privileges, leading to full server compromise.

Vulnerability

This is a DLL hijacking flaw (CWE-427) where the Process Optimization service incorrectly loads arbitrary code. The attack requires the user to be authenticated with standard OS-level privileges.

Business impact

The ability for a standard user to escalate privileges to the OS System level represents a critical risk to organizational security. Successful exploitation could result in the total compromise of the Model Application Server, leading to unauthorized data access, lateral movement within the OT environment, and significant operational disruption. With a CVSS score of 8.8, this vulnerability is classified as High severity and demands immediate attention.

Remediation

Immediate Action: Update the affected software to AVEVA Process Optimization version 2025 as specified in the vendor security bulletin AVEVA-2026-001.

Proactive Monitoring: Review system logs for unauthorized service modifications and monitor for the execution of unexpected binaries or processes originating from the Process Optimization service account.

Compensating Controls: Restrict access to the Model Application Server to only authorized personnel and implement strict file system permissions to prevent standard users from placing malicious DLL files in service search paths.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete system compromise, administrators should prioritize the deployment of the version 2025 update. Organizations should verify their current version of AVEVA Process Optimization immediately and schedule the upgrade during the next available maintenance window to mitigate the risk of local privilege escalation.

Sources

Originally found and disclosed by Christopher Wu of Veracode reported these vulnerabilities to AVEVA., per the CVE Program record.