Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Critical AVEVA Software Flaws Allow Remote Code Execution With SYSTEM Privileges

AVEVA has identified seven critical and high-severity vulnerabilities within its Process Optimization software (formerly ROMeo), which could allow attackers to execute remote code with SYSTEM privileges, resulting in the potential compromise of…

AVEVA has identified seven critical and high-severity vulnerabilities within its Process Optimization software (formerly ROMeo), which could allow attackers to execute remote code with SYSTEM privileges, resulting in the potential compromise of industrial control systems.

The security bulletin, released on Tue, Jan 13, 2026, affects AVEVA Process Optimization version 2024.1 and all preceding versions.

The most critical vulnerability, identified as CVE-2025-61937, has been assigned a maximum CVSSv4.0 score of 10.0. It represents an unauthenticated remote code execution flaw via the software's API.

Exploitation does not require user interaction and may enable attackers to obtain SYSTEM-level privileges on the "taoimr" service, which could lead to a complete compromise of the Model Application Server.

The disclosed vulnerabilities include three additional critical-severity flaws, each with a CVSS score of 9.3.

CVE-2025-64691: Allows authenticated attackers with standard OS user privileges to inject malicious code through TCL Macro script tampering, escalating privileges to SYSTEM level. CVE-2025-61943: Involves SQL injection in the Captive Historian component, enabling code execution under SQL Server administrative privileges. CVE-2025-65118: Exploits DLL hijacking vulnerabilities, allowing privilege escalation via arbitrary code loading in Process Optimization services.

The bulletin also addresses three high-severity vulnerabilities:

CVE-2025-64729 (CVSS 8.6): Enables privilege escalation through project file tampering due to missing access control lists. CVE-2025-65117 (CVSS 8.5): Allows authenticated designer users to embed malicious OLE objects into graphics for privilege escalation. CVE-2025-64769 (CVSS 7.6): Exposes sensitive information through unencrypted transmission channels, creating opportunities for man-in-the-middle attacks.

The security bulletin, released on Tue, Jan 13, 2026, affects AVEVA Process Optimization version 2024.1 and all preceding versions.
Vanessa Ray · Thehackingpost

CVE Vulnerability Type CVSS Score

CVE-2025-61937 Remote Code Execution via API 10.0 Critical

CVE-2025-64691 Code Injection (TCL Macro) 9.3 Critical

CVE-2025-61943 SQL Injection 9.3 Critical

CVE-2025-65118 DLL Hijacking 9.3 Critical

CVE-2025-64729 Missing Authorization 8.6 High

Advertisement

CVE-2025-65117 Malicious OLE Objects 8.5 High

CVE-2025-64769 Cleartext Transmission 7.6 High

AVEVA advises an immediate upgrade to AVEVA Process Optimization 2025 or later to address all identified vulnerabilities.

Organizations unable to apply patches promptly should implement temporary defensive measures, including firewall rules restricting the taoimr service to trusted sources on ports 8888/8889, access control lists limiting write access to installation directories, and maintaining strict chain-of-custody protocols for project files.

The vulnerabilities were discovered by security researcher Christopher Wu from Veracode during an AVEVA-sponsored penetration testing engagement, with coordination provided by CISA for advisory publication and CVE assignment.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories