Executive brief
AzeoTech DAQFactory, a software suite used for data acquisition and control in industrial environments, is vulnerable to a memory corruption flaw. An attacker could exploit this by tricking a user into opening a specially crafted .ctl file, potentially allowing the attacker to take control of the system or disrupt operations. This could lead to unauthorized access to sensitive industrial data or a complete shutdown of the monitoring process.
Technical details
A Use After Free (CWE-416) vulnerability exists in AzeoTech DAQFactory version 20.7 (Build 2555) and earlier. The flaw is triggered during the parsing of specially crafted .ctl files, where the application attempts to access memory that has already been freed. This results in memory corruption that an attacker can leverage to execute arbitrary code in the context of the current process. Exploitation requires local access and user interaction, specifically convincing a user to open a malicious document. AzeoTech has addressed this vulnerability in Release 21.1.
Affected products
- AzeoTech DAQFactory <= 20.7 Build 2555
Timeline
- 2025-12-11: disclosed
- 2025-12-11: advisory
- 2025-12-30: patched: Update A of the advisory confirms Release 21.1 as the fix.