Junglewise Threat Intelligence

CVE-2025-66590: AzeoTech DAQFactory out-of-bounds write in .ctl file parsing

CVE-2025-66590 · Severity: high · CVSS 7.8 · Published 2025-12-11

Technologies: Azeotech Daqfactory. Vendors: Azeotech.

Executive brief

AzeoTech DAQFactory, a software suite used for data acquisition and industrial automation, is vulnerable to a memory corruption flaw. An attacker can exploit this by tricking a user into opening a specially crafted malicious project file (.ctl). Successful exploitation could allow the attacker to crash the system or gain full control over the computer running the software, potentially disrupting industrial operations.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in AzeoTech DAQFactory release 20.7 (Build 2555) and prior. The flaw is triggered when the application improperly handles memory allocation while parsing specially crafted .ctl files. An attacker can exploit this by providing a malicious file to a user; upon opening, the program writes data past the end of an allocated buffer. This memory corruption can be leveraged to achieve arbitrary code execution in the context of the current process or cause a denial-of-service (system crash). The vulnerability is addressed in DAQFactory Release 21.1.

Affected products

  • AzeoTech DAQFactory 20.7 (Build 2555) and earlier

Timeline

  • 2025-12-11: disclosed
  • 2025-12-11: advisory: Initial CISA ICSA-25-345-03 advisory published
  • 2025-12-30: patched: Update A released with remediation details for version 21.1

References

Related threats