Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cvm5-pcmg-6888

Опубликовано: 16 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 7.4

Описание

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.

EPSS

Процентиль: 1%
0.00011
Низкий

8.5 High

CVSS4

7.4 High

CVSS3

Дефекты

CWE-676

Связанные уязвимости

CVSS3: 7.4
nvd
21 день назад

The vulnerability, if exploited, could allow an authenticated miscreant (Process Optimization Designer User) to embed OLE objects into graphics, and escalate their privileges to the identity of a victim user who subsequently interacts with the graphical elements.

CVSS3: 5.8
fstec
24 дня назад

Уязвимость программного обеспечения для онлайн-моделирования и оптимизации процессов AVEVA Process Optimization, связанная с использованием потенциально опасных функций, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 1%
0.00011
Низкий

8.5 High

CVSS4

7.4 High

CVSS3

Дефекты

CWE-676