PT-2025-50737 · Azeotech · Daqfactory

Published

2025-12-11

·

Updated

2025-12-17

·

CVE-2025-66586

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AzeoTech DAQFactory version 20.7 (Build 2555)
Description AzeoTech DAQFactory release 20.7 (Build 2555) contains a flaw related to improper handling of resources. Specifically, an Access of Resource Using Incompatible Type issue exists when processing specially designed .ctl files. This can lead to memory corruption, potentially allowing an attacker to execute code within the current process.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Fix

Type Confusion

Weakness Enumeration

Related Identifiers

CVE-2025-66586
ZDI-25-1131
ZDI-25-1132
ZDI-25-1133
ZDI-25-1134

Affected Products

Daqfactory