CVE-2025-65117: AVEVA Process Optimization Use of Potentially Dangerous Function
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65117?
CVE-2025-65117 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-65117?
To mitigate CVE-2025-65117, users should apply the latest security updates provided by AVEVA for the Process Optimization software.
Who is affected by CVE-2025-65117?
CVE-2025-65117 affects authenticated users of AVEVA Process Optimization who can exploit the vulnerability.
What type of vulnerability is CVE-2025-65117?
CVE-2025-65117 is classified as a use of potentially dangerous function vulnerability.
What can an attacker achieve by exploiting CVE-2025-65117?
An attacker exploiting CVE-2025-65117 may be able to escalate privileges to that of a victim user by embedding OLE objects into graphics.