Junglewise Threat Intelligence

CVE-2025-66585: AzeoTech DAQFactory use after free in .ctl file parsing

CVE-2025-66585 · Severity: high · CVSS 7.8 · Published 2025-12-11

Technologies: Azeotech Daqfactory. Vendors: Azeotech.

Executive brief

AzeoTech DAQFactory, a software suite used for data acquisition and control in industrial environments, is vulnerable to a memory corruption flaw. An attacker could exploit this by tricking a user into opening a specially crafted .ctl file, potentially allowing the attacker to take control of the system or disrupt operations. This could lead to unauthorized access to sensitive industrial data or a complete shutdown of the monitoring process.

Technical details

A Use After Free (CWE-416) vulnerability exists in AzeoTech DAQFactory version 20.7 (Build 2555) and earlier. The flaw is triggered during the parsing of specially crafted .ctl files, where the application attempts to access memory that has already been freed. This results in memory corruption that an attacker can leverage to execute arbitrary code in the context of the current process. Exploitation requires local access and user interaction, specifically convincing a user to open a malicious document. AzeoTech has addressed this vulnerability in Release 21.1.

Affected products

  • AzeoTech DAQFactory <= 20.7 Build 2555

Timeline

  • 2025-12-11: disclosed
  • 2025-12-11: advisory
  • 2025-12-30: patched: Update A of the advisory confirms Release 21.1 as the fix.

References

Related threats