
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-30033 is a DLL hijacking vulnerability affecting a shared setup (web installer) component used across a large number of Siemens industrial software products. The flaw allows an attacker to place a malicious DLL in a location searched by the installer, which is then loaded and executed when a legitimate user runs the affected setup component. It was published on August 12, 2025, and affects dozens of Siemens product lines including SIMATIC, SINAMICS, WinCC, TIA Portal, and many others. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (Siemens CERT, CISA ICS Advisory).
The root cause is classified as CWE-427 (Uncontrolled Search Path Element): the affected Siemens web installer/setup component does not adequately control the directories it searches when loading DLLs, making it susceptible to DLL search order hijacking (MITRE ATT&CK T1574.001). An attacker who can place a malicious DLL in a directory that is searched before the legitimate DLL location — such as the current working directory or a user-writable path — can cause the installer to load and execute the attacker-controlled code. Exploitation requires local access and user interaction (a legitimate user must run the installer), but no privileges are required. The vulnerability is mapped to CAPEC-471 (Search Order Hijacking) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) (Siemens CERT, CISA ICS Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the user running the installer, resulting in high confidentiality, integrity, and availability impact on the affected system. Because the vulnerability is triggered during software installation — a process that often runs with elevated privileges — the attacker's code may execute with administrator-level rights, potentially enabling full system compromise, credential theft, or persistent access. The breadth of affected products (spanning SIMATIC PCS 7, WinCC, TIA Portal, SINAMICS, SINEC NMS, and many others) means the attack surface is extremely wide across Siemens-based industrial environments (Siemens CERT, CISA ICS Advisory).
%TEMP%, %USERPROFILE%, or the directory from which the installer is launched).setup.exe, Siemens web installer executables) spawning unexpected child processes or loading DLLs from non-standard paths (detectable via Sysmon Event ID 7 — Image Loaded, with unsigned or unexpected DLL paths).Siemens has released patches for several affected products; administrators should consult the official advisory (SSA-282044) for the full list of fixed versions. Notable patched versions include: SIMATIC ProSave V19 Update 4, TeleControl Server Basic V3.1.2.2, TIA Administrator V3.0.6, SIMATIC NET PC Software V20.0 Update 1, SIMATIC S7-PLCSIM Advanced V7.0 Update 1, SIMATIC S7-PLCSIM V20 Update 1, SIMATIC WinCC V8.1 Update 3, SIMATIC PCS neo V6.0 SP1, Automation License Manager V6.2 Upd3, SINEC NMS V4.0, and SIMATIC S7-Fail-safe Configuration Tool V4.0.1. For products without a fix, Siemens recommends running installers only from trusted, controlled directories; avoiding running setup components from user-writable or shared network locations; and applying the principle of least privilege. Organizations should monitor for unauthorized DLL files in installer directories and restrict write access to directories used during software installation (Siemens CERT, CISA ICS Advisory).
Siemens published a formal product security advisory (SSA-282044) on August 12, 2025, disclosing the vulnerability and providing remediation guidance for the extensive list of affected products. CISA issued ICS Advisory ICSA-25-226-22 on the same date, highlighting the broad industrial impact. Community coverage noted the unusually large number of affected Siemens products sharing the vulnerable setup component, with Windows-focused forums discussing the DLL hijacking mechanics and mitigation steps for industrial operators (CISA ICS Advisory, Windows Forum).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."