Schneider Electric EcoStruxure Process Expert Improper Privilege Management Vulnerability

Vulnerability

A vulnerability allowing improper privilege management has been identified in Schneider Electric's EcoStruxure Process Expert and EcoStruxure Process Expert for AVEVA System Platform. This vulnerability affects versions 2020R2, 2021, and 2023, prior to v4.8.0.5715. The issue arises when an attacker with standard privileges modifies the executable path of certain Windows services, one of which manages audit trail data while the other handles client requests. Exploitation of this vulnerability requires restarting the affected services, and could lead to a local privilege escalation, causing a loss of confidentiality, integrity, and availability on the engineering workstation.

Impact

Exploitation of this vulnerability could result in a local privilege escalation, allowing an attacker to gain elevated rights and potentially misuse them, leading to unauthorized access or modifications. In the context of the affected engineering workstation, this could disrupt operations, cause data loss, or interfere with the management of control projects and SCADA supervision tasks.

Remediation

Users of EcoStruxure Process Expert should upgrade to version 2023 (v4.8.0.5715), ensuring to uninstall the previous version 2023 (v4.8.0.5115) before installation. For EcoStruxure Process Expert for AVEVA System Platform, Schneider Electric is developing a remediation plan for future versions that will address this vulnerability. Until then, users should allow only admin users to configure Windows services by restricting execute permissions of the service control utility, and can use McAfee Application and Change Control software to whitelist applications. For additional guidance, refer to the Cybersecurity Application Note available on the Schneider Electric website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
3.1
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.