---
cve: "CVE-2025-65118"
severity: "CRITICAL"
cvss: 9.3
epss: "26%"
vendor: "AVEVA"
kev: false
exploited: false
published: "2026-01-16 02:16:46"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T16:52:23+02:00"
---

# CVE-2025-65118

> 9.3 CRITICAL · 🧪 PoC

## Beschreibung

The vulnerability, if exploited, could allow an authenticated miscreant 
(OS Standard User) to trick Process Optimization services into loading 
arbitrary code and escalate privileges to OS System, potentially 
resulting in complete compromise of the Model Application Server.

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://www.aveva.com/en/support-and-success/cyber-security-updates/>
- <https://softwaresupportsp.aveva.com/en-US/downloads/products/details/a643eaa3-0d85-4fde-ac11-5239e87a68ea>
- <https://www.cisa.gov/news-events/ics-advisories/icsa-26-015-01>
- <https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-015-01.json>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-65118) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
