github.com
https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json CVE-2025-65117
HIGH
AVEVA Process Optimization Use of Potentially Dangerous Function
Record summary
CVE-2025-65117 has a selected CVSS score of 8.5 (high).
Description
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 16, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Process OptimizationBrowse AVEVA / Process OptimizationDefault status: unaffected | CVE List | Through 2024.1 | affected |
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-65117 softwaresupportsp.aveva.com
https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea aveva.com
https://www.aveva.com/en/support-and-success/cyber-security-updates cisa.gov
https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01