Critical AVEVA Software Flaws Allow Remote Code Execution With SYSTEM Privileges
AVEVA has identified seven critical and high-severity vulnerabilities within its Process Optimization software (formerly ROMeo), which could allow attackers to execute remote code with SYSTEM privileges, resulting in the potential compromise of…
AVEVA has identified seven critical and high-severity vulnerabilities within its Process Optimization software (formerly ROMeo), which could allow attackers to execute remote code with SYSTEM privileges, resulting in the potential compromise of industrial control systems.
The security bulletin, released on Tue, Jan 13, 2026, affects AVEVA Process Optimization version 2024.1 and all preceding versions.
The most critical vulnerability, identified as CVE-2025-61937, has been assigned a maximum CVSSv4.0 score of 10.0. It represents an unauthenticated remote code execution flaw via the software's API.
Exploitation does not require user interaction and may enable attackers to obtain SYSTEM-level privileges on the "taoimr" service, which could lead to a complete compromise of the Model Application Server.
The disclosed vulnerabilities include three additional critical-severity flaws, each with a CVSS score of 9.3.
CVE-2025-64691: Allows authenticated attackers with standard OS user privileges to inject malicious code through TCL Macro script tampering, escalating privileges to SYSTEM level. CVE-2025-61943: Involves SQL injection in the Captive Historian component, enabling code execution under SQL Server administrative privileges. CVE-2025-65118: Exploits DLL hijacking vulnerabilities, allowing privilege escalation via arbitrary code loading in Process Optimization services.
The bulletin also addresses three high-severity vulnerabilities:
CVE-2025-64729 (CVSS 8.6): Enables privilege escalation through project file tampering due to missing access control lists. CVE-2025-65117 (CVSS 8.5): Allows authenticated designer users to embed malicious OLE objects into graphics for privilege escalation. CVE-2025-64769 (CVSS 7.6): Exposes sensitive information through unencrypted transmission channels, creating opportunities for man-in-the-middle attacks.
The security bulletin, released on Tue, Jan 13, 2026, affects AVEVA Process Optimization version 2024.1 and all preceding versions.
CVE Vulnerability Type CVSS Score
CVE-2025-61937 Remote Code Execution via API 10.0 Critical
CVE-2025-64691 Code Injection (TCL Macro) 9.3 Critical
CVE-2025-61943 SQL Injection 9.3 Critical
CVE-2025-65118 DLL Hijacking 9.3 Critical
CVE-2025-64729 Missing Authorization 8.6 High
CVE-2025-65117 Malicious OLE Objects 8.5 High
CVE-2025-64769 Cleartext Transmission 7.6 High
AVEVA advises an immediate upgrade to AVEVA Process Optimization 2025 or later to address all identified vulnerabilities.
Organizations unable to apply patches promptly should implement temporary defensive measures, including firewall rules restricting the taoimr service to trusted sources on ports 8888/8889, access control lists limiting write access to installation directories, and maintaining strict chain-of-custody protocols for project files.
The vulnerabilities were discovered by security researcher Christopher Wu from Veracode during an AVEVA-sponsored penetration testing engagement, with coordination provided by CISA for advisory publication and CVE assignment.
Based on reporting by GBHackers.
