CVE-2025-65117
The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H
- EPSS probability
- 0.21%
- CWE
- CWE-676
- Published
- 2026-01-16
- Last modified
- 2026-03-12
Affected products
- AVEVA Process Optimization
Weakness type
Related vulnerabilities
- CVE-2025-14601 — vsDesk Task Scheduler OS Command Injection
- CVE-2026-14501 — Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub
- CVE-2026-54499 — Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- CVE-2025-67604 — A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through...
- CVE-2024-50307 — Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows)...
- CVE-2024-38434 — Unitronics Vision PLC - CWE-676: Use of Potentially Dangerous Function
- CVE-2022-39063 — When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for...
- CVE-2021-27474 — Rockwell Automation FactoryTalk AssetCentre Use of Potentially Dangerous Function