
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-66588 is an Access of Uninitialized Pointer vulnerability (CWE-824) in AzeoTech DAQFactory release 20.7 (Build 2555) and earlier versions that can be exploited to achieve arbitrary code execution. The vulnerability was disclosed on December 11, 2025, via CISA ICS Advisory ICSA-25-345-03, and is part of a broader set of memory-safety flaws affecting the same product. All versions of DAQFactory prior to Release 21.1 are affected. The CVSS v3.1 base score assigned by CISA is 7.8 (High), while NVD initially scored it 9.8 (Critical); the CVSS v4.0 score is 8.4 (High) (CISA Advisory, Red Hat CVE).
The root cause is CWE-824 (Access of Uninitialized Pointer): DAQFactory fails to properly initialize a pointer before use during the parsing of .ctl project files, allowing an attacker to influence the uninitialized memory value and redirect code execution. Exploitation requires an attacker to supply a specially crafted malicious .ctl file and have a local user open it — meaning user interaction is required and the attack vector is local, not network-based. The vulnerability is not remotely exploitable on its own; it relies on social engineering or file-delivery mechanisms to get a victim to load the malicious document. CVE-2025-66588 was reported to CISA by researcher Michael Heinzl and is one of five related memory-corruption CVEs (CVE-2025-66585 through CVE-2025-66590) disclosed in the same advisory (CISA Advisory, CSAF JSON).
Successful exploitation allows an attacker to execute arbitrary code in the context of the DAQFactory process, with the same privileges as the running application. This can result in full compromise of the affected system, including unauthorized data access (confidentiality), modification of industrial control data or configurations (integrity), and disruption of DAQFactory operations (availability). Given DAQFactory's role in critical manufacturing and industrial data acquisition environments, exploitation could have downstream effects on operational technology (OT) processes (CISA Advisory).
No public proof-of-concept exploit code has been identified, and CISA has confirmed no known public exploitation specifically targeting this vulnerability at the time of disclosure. The vulnerability is not remotely exploitable and requires user interaction (opening a malicious .ctl file), which limits opportunistic exploitation. The EPSS score is approximately 0.016% (0.000160), indicating a very low probability of exploitation in the near term. This CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA Advisory, Red Hat CVE).
.ctl) that triggers the uninitialized pointer access during parsing — this requires knowledge of the DAQFactory file format and the specific code path that fails to initialize the pointer..ctl file where a DAQFactory operator is likely to open it..ctl file into DAQFactory release 20.7 (Build 2555) or earlier. This is the required user interaction step..ctl files in DAQFactory project directories; .ctl files stored in locations writable by non-administrative users.cmd.exe, powershell.exe, or network utilities) following the opening of a .ctl file..ctl file parsing; unexpected process termination events associated with the DAQFactory process..ctl file is opened, which may indicate post-exploitation activity (CISA Advisory).AzeoTech has released DAQFactory Release 21.1, which addresses CVE-2025-66588 and all related vulnerabilities in the advisory. Organizations should upgrade immediately. As interim mitigations, AzeoTech recommends: (1) avoid opening .ctl files from unknown or untrusted sources; (2) restrict .ctl file storage directories to be writable only by administrative users; (3) use DAQFactory's "Safe Mode" when loading documents that have been outside organizational control; and (4) apply document editing passwords to DAQFactory projects. CISA additionally recommends isolating ICS networks behind firewalls, minimizing internet exposure, and using VPNs for any required remote access (CISA Advisory).
CISA published ICS Advisory ICSA-25-345-03 on December 11, 2025, coordinating disclosure of this and four related DAQFactory vulnerabilities. The advisory was updated on December 30, 2025 (Update A) to refine researcher attribution and remove two duplicate CVEs. No significant independent researcher commentary, social media discussion, or media coverage beyond standard vulnerability aggregator republication has been identified for this specific CVE (CISA Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."