← Retour aux CVEs
CVE-2025-65117
HIGH7.4
Description
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.
Details CVE
Score CVSS v3.17.4
SeveriteHIGH
Vecteur CVSSCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Vecteur d'attaqueLOCAL
ComplexiteLOW
Privileges requisHIGH
Interaction utilisateurREQUIRED
Publie1/16/2026
Derniere modification1/22/2026
Sourcenvd
Observations honeypot0
Produits affectes
aveva:process_optimization
Faiblesses (CWE)
CWE-676
References
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json(ics-cert@hq.dhs.gov)
https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea(ics-cert@hq.dhs.gov)
https://www.aveva.com/en/support-and-success/cyber-security-updates/(ics-cert@hq.dhs.gov)
https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01(ics-cert@hq.dhs.gov)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.