CVE-2025-65118: AVEVA Process Optimization Uncontrolled Search Path Element
The vulnerability, if exploited, could allow an authenticated miscreant (OS Standard User) to trick Process Optimization services into loading arbitrary code and escalate privileges to OS System, potentially resulting in complete compromise of the Model Application Server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-65118?
CVE-2025-65118 is considered a high-severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2025-65118?
To fix CVE-2025-65118, apply the latest security updates provided by AVEVA for the Process Optimization software.
What type of attack does CVE-2025-65118 allow?
CVE-2025-65118 allows authenticated users to exploit uncontrolled search path elements and load arbitrary code.
Who is affected by CVE-2025-65118?
Users of AVEVA Process Optimization software are affected by CVE-2025-65118.
What are the potential consequences of exploiting CVE-2025-65118?
Exploiting CVE-2025-65118 could lead to complete system compromise and unauthorized access to sensitive information.