CVE-2025-66588
AzeoTech DAQFactory vulnerability analysis and mitigation

Overview

CVE-2025-66588 is an Access of Uninitialized Pointer vulnerability (CWE-824) in AzeoTech DAQFactory release 20.7 (Build 2555) and earlier versions that can be exploited to achieve arbitrary code execution. The vulnerability was disclosed on December 11, 2025, via CISA ICS Advisory ICSA-25-345-03, and is part of a broader set of memory-safety flaws affecting the same product. All versions of DAQFactory prior to Release 21.1 are affected. The CVSS v3.1 base score assigned by CISA is 7.8 (High), while NVD initially scored it 9.8 (Critical); the CVSS v4.0 score is 8.4 (High) (CISA Advisory, Red Hat CVE).

Technical details

The root cause is CWE-824 (Access of Uninitialized Pointer): DAQFactory fails to properly initialize a pointer before use during the parsing of .ctl project files, allowing an attacker to influence the uninitialized memory value and redirect code execution. Exploitation requires an attacker to supply a specially crafted malicious .ctl file and have a local user open it — meaning user interaction is required and the attack vector is local, not network-based. The vulnerability is not remotely exploitable on its own; it relies on social engineering or file-delivery mechanisms to get a victim to load the malicious document. CVE-2025-66588 was reported to CISA by researcher Michael Heinzl and is one of five related memory-corruption CVEs (CVE-2025-66585 through CVE-2025-66590) disclosed in the same advisory (CISA Advisory, CSAF JSON).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the DAQFactory process, with the same privileges as the running application. This can result in full compromise of the affected system, including unauthorized data access (confidentiality), modification of industrial control data or configurations (integrity), and disruption of DAQFactory operations (availability). Given DAQFactory's role in critical manufacturing and industrial data acquisition environments, exploitation could have downstream effects on operational technology (OT) processes (CISA Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and CISA has confirmed no known public exploitation specifically targeting this vulnerability at the time of disclosure. The vulnerability is not remotely exploitable and requires user interaction (opening a malicious .ctl file), which limits opportunistic exploitation. The EPSS score is approximately 0.016% (0.000160), indicating a very low probability of exploitation in the near term. This CVE is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA Advisory, Red Hat CVE).

Exploitation steps

  1. Craft malicious .ctl file: Create a specially crafted AzeoTech DAQFactory project file (.ctl) that triggers the uninitialized pointer access during parsing — this requires knowledge of the DAQFactory file format and the specific code path that fails to initialize the pointer.
  2. Deliver the file to the target: Use social engineering (e.g., phishing email, shared network drive, or supply chain compromise) to place the malicious .ctl file where a DAQFactory operator is likely to open it.
  3. Induce user to open the file: Convince the target user to load the malicious .ctl file into DAQFactory release 20.7 (Build 2555) or earlier. This is the required user interaction step.
  4. Trigger uninitialized pointer dereference: When DAQFactory parses the crafted file, it accesses an uninitialized pointer, allowing the attacker to control the memory address referenced and redirect execution flow.
  5. Achieve arbitrary code execution: The attacker's payload executes in the context of the DAQFactory process, enabling further actions such as persistence, lateral movement within the OT network, or data exfiltration (CISA Advisory).

Indicators of compromise

  • File System: Presence of unexpected or externally sourced .ctl files in DAQFactory project directories; .ctl files stored in locations writable by non-administrative users.
  • Process: Unusual child processes spawned by the DAQFactory executable (e.g., cmd.exe, powershell.exe, or network utilities) following the opening of a .ctl file.
  • Logs: DAQFactory application crash logs or Windows Event Log entries indicating access violations or unhandled exceptions during .ctl file parsing; unexpected process termination events associated with the DAQFactory process.
  • Network: Unexpected outbound network connections from the DAQFactory host to external IPs shortly after a .ctl file is opened, which may indicate post-exploitation activity (CISA Advisory).

Mitigation and workarounds

AzeoTech has released DAQFactory Release 21.1, which addresses CVE-2025-66588 and all related vulnerabilities in the advisory. Organizations should upgrade immediately. As interim mitigations, AzeoTech recommends: (1) avoid opening .ctl files from unknown or untrusted sources; (2) restrict .ctl file storage directories to be writable only by administrative users; (3) use DAQFactory's "Safe Mode" when loading documents that have been outside organizational control; and (4) apply document editing passwords to DAQFactory projects. CISA additionally recommends isolating ICS networks behind firewalls, minimizing internet exposure, and using VPNs for any required remote access (CISA Advisory).

Community reactions

CISA published ICS Advisory ICSA-25-345-03 on December 11, 2025, coordinating disclosure of this and four related DAQFactory vulnerabilities. The advisory was updated on December 30, 2025 (Update A) to refine researcher attribution and remove two duplicate CVEs. No significant independent researcher commentary, social media discussion, or media coverage beyond standard vulnerability aggregator republication has been identified for this specific CVE (CISA Advisory).

Additional resources


SourceThis report was generated using AI

Related AzeoTech DAQFactory vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12921HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoNoJun 25, 2026
CVE-2026-12390HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoNoJun 18, 2026
CVE-2025-66590HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025
CVE-2025-66589HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025
CVE-2025-66588HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management