Junglewise Threat Intelligence

CVE-2025-66588: AzeoTech DAQFactory uninitialized pointer access

CVE-2025-66588 · Severity: high · CVSS 7.8 · Published 2025-12-11

Technologies: Azeotech Daqfactory. Vendors: Azeotech.

Executive brief

AzeoTech DAQFactory, a software suite used for data acquisition and industrial automation, is vulnerable to a memory handling error. An attacker could exploit this by tricking a user into opening a specially crafted .ctl file, potentially allowing the attacker to take control of the system or execute unauthorized commands. This could lead to a complete compromise of the workstation used to manage industrial processes.

Technical details

An Access of Uninitialized Pointer (CWE-824) vulnerability exists in AzeoTech DAQFactory release 20.7 (Build 2555) and earlier. The flaw is triggered when the application attempts to access a pointer that has not been properly initialized during the parsing of a .ctl document. An attacker can exploit this by providing a malicious file to a user; upon opening the file, the application may execute arbitrary code in the context of the current process. This vulnerability requires user interaction (opening a file) and is addressed in DAQFactory Release 21.1.

Affected products

  • AzeoTech DAQFactory <= 20.7 Build 2555

Timeline

  • 2025-12-11: disclosed
  • 2025-12-11: advisory
  • 2025-12-30: other: Advisory revised (Update A)

References

Related threats