{"id":9992,"date":"2026-01-20T10:03:43","date_gmt":"2026-01-20T10:03:43","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/20\/critical-aveva-software-vulnerabilities-enables-remote-code-execution-under-system-privileges\/"},"modified":"2026-01-20T10:03:43","modified_gmt":"2026-01-20T10:03:43","slug":"critical-aveva-software-vulnerabilities-enables-remote-code-execution-under-system-privileges","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/20\/critical-aveva-software-vulnerabilities-enables-remote-code-execution-under-system-privileges\/","title":{"rendered":"Critical AVEVA Software Vulnerabilities Enables Remote Code Execution Under System Privileges"},"content":{"rendered":"<p>    Critical AVEVA Software Vulnerabilities Enables Remote Code Execution Under System Privileges<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Seven vulnerabilities were disclosed in Process Optimization (formerly ROMeo) 2024.1 and earlier on January 13, 2026, including a critical flaw enabling unauthenticated <a href=\"https:\/\/cybersecuritynews.com\/citrix-windows-virtual-delivery-agent-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">SYSTEM-level<\/a> remote code execution.<\/p>\n<p>The most severe vulnerability enables unauthenticated attackers to achieve remote code execution under system privileges, posing an immediate risk to industrial process control environments worldwide.\u200b<\/p>\n<p>The primary threat stems from a critical code injection vulnerability in the application\u2019s <a href=\"https:\/\/cybersecuritynews.com\/best-api-protection-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">API layer<\/a>. An unauthenticated attacker can exploit this flaw to execute arbitrary code with full system privileges on the \u201ctaoimr\u201d service.<\/p>\n<p>Potentially compromising the entire Model Application Server and connected infrastructure.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-vulnerability-summary\"><strong>Vulnerability Summary<\/strong><\/h2>\n<p>This attack requires no user interaction, is low-complexity, and can be executed remotely over the network, making it exceptionally dangerous for organizations running vulnerable versions.\u200b<\/p>\n<p>Additional severe vulnerabilities include <a href=\"https:\/\/cybersecuritynews.com\/microsoft-powerpoint-code-injection-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">code injection<\/a> via macro functionality that allows authenticated users to escalate from standard OS user to system-level privileges.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE ID<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Type<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">CVSS v4.0<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Severity<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Impact<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-61937<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Remote Code Execution (API)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">10.0<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Critical<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Unauthenticated RCE under system privileges<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-64691<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Code Injection (Macros)<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">9.3<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Critical<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Privilege escalation via TCL scripts<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-61943<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\"><a href=\"https:\/\/cybersecuritynews.com\/django-vulnerabilities-sql-injection-and-dos-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">SQL Injection<\/a><\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">9.3<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Critical<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">SQL Server admin code execution<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-65118<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">DLL Hijacking<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">9.3<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Critical<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">System privilege escalation<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-64729<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Missing ACLs<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">8.6<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">High<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Project file tampering &amp; privilege escalation<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-65117<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Embedded OLE Objects<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">8.5<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">High<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Malicious content delivery<\/td>\n<\/tr>\n<tr>\n<td class=\"has-text-align-left\" data-align=\"left\">CVE-2025-64769<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Cleartext Transmission<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">7.6<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">High<\/td>\n<td class=\"has-text-align-left\" data-align=\"left\">Data interception via <a href=\"https:\/\/cybersecuritynews.com\/yono-sbi-banking-app-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Man-in-the-Middle<\/a>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>SQL injection flaws in the Captive Historian component that grant attackers SQL Server administrative access.<\/p>\n<p>A <a href=\"https:\/\/cybersecuritynews.com\/notepad-hijacking-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">DLL hijacking<\/a> vulnerability enables authenticated users to load arbitrary code and elevate their privileges to system-level.<\/p>\n<p>These attack vectors collectively demonstrate sophisticated exploitation pathways that could completely compromise affected systems.\u200b<\/p>\n<p>AVEVA <a href=\"https:\/\/www.aveva.com\/content\/dam\/aveva\/documents\/support\/cyber-security-updates\/SecurityBulletin_AVEVA-2026-001.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">recommends<\/a> immediate action: organizations should upgrade to AVEVA Process Optimization 2025 or higher to patch all identified vulnerabilities.<\/p>\n<p>As an interim defensive measure, administrators should implement network <a href=\"https:\/\/cybersecuritynews.com\/microsoft-azure-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">firewall rules<\/a> restricting the taoimr service (default ports 8888\/8889) to trusted sources only.<\/p>\n<p>Apply strict access control lists to installation and data folders, and maintain rigorous change management for project files.<\/p>\n<p>The vulnerabilities were discovered during a planned <a href=\"https:\/\/cybersecuritynews.com\/penetration-testing-companies\/\" target=\"_blank\" rel=\"noreferrer noopener\">penetration test<\/a> by Veracode security researcher Christopher Wu and coordinated with CISA.\u200b<\/p>\n<p>Organizations operating AVEVA Process Optimization environments should prioritize <a href=\"https:\/\/cybersecuritynews.com\/linux-kernel-patching\/\" target=\"_blank\" rel=\"noreferrer noopener\">patching<\/a> immediately to prevent exploitation of these critical flaws in their industrial control systems infrastructure.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/aveva-software-vulnerabilities\/\">Critical AVEVA Software Vulnerabilities Enables Remote Code Execution Under System Privileges<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/aveva-software-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Critical AVEVA Software Vulnerabilities Enables Remote Code Execution Under System Privileges Seven vulnerabilities were disclosed in Process Optimization (formerly ROMeo) 2024.1 and earlier on January 13, 2026, including a critical flaw enabling unauthenticated SYSTEM-level remote code execution. The most severe vulnerability enables unauthenticated attackers to achieve remote code execution under system privileges, posing an immediate [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2015,129,63,416],"tags":[130],"class_list":["post-9992","post","type-post","status-publish","format-standard","hentry","category-cve-vulnerabilities","category-cyber-security","category-cyber-security-news","category-vulnerabilities","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9992"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9992"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9992\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9992"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9992"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9992"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}