Executive brief
AzeoTech DAQFactory, a software suite used for data acquisition and industrial automation, is vulnerable to a memory corruption flaw. An attacker can exploit this by tricking a user into opening a specially crafted .ctl project file. Successful exploitation could allow the attacker to take control of the system or disrupt industrial operations.
Technical details
A type confusion vulnerability (CWE-843) exists in AzeoTech DAQFactory release 20.7 (Build 2555) and earlier. The flaw occurs during the parsing of .ctl files when the application accesses a resource using an incompatible type, leading to memory corruption. An attacker can exploit this by providing a malicious .ctl file that, when opened by a user, triggers the vulnerability. This can result in arbitrary code execution in the context of the current process. The issue is resolved in DAQFactory Release 21.1.
Affected products
- AzeoTech DAQFactory <= 20.7 Build 2555
Timeline
- 2025-12-11: disclosed
- 2025-12-11: advisory
- 2025-12-30: other: Advisory updated by CISA