CVE-2025-66589
AzeoTech DAQFactory vulnerability analysis and mitigation

Overview

CVE-2025-66589 is an Out-of-bounds Read vulnerability (CWE-125) in AzeoTech DAQFactory release 20.7 (Build 2555), a data acquisition and HMI software used in industrial control systems. The flaw allows an attacker to cause the program to read data past the end of an allocated buffer during CTL file parsing, potentially leading to information disclosure or a system crash. It was publicly disclosed on December 11, 2025, via a CISA ICS advisory (ICSA-25-345-03), with Zero Day Initiative advisories published on December 19, 2025. The vulnerability carries a CVSS v3.1 score of 7.8 (High) per CISA and a CVSS v4.0 score of 8.4 (High) (CISA Advisory, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read) and is triggered during the parsing of specially crafted .ctl project files in AzeoTech DAQFactory. An attacker who can supply a malicious .ctl file to a victim user can cause the application to read memory beyond the bounds of an allocated buffer, which may expose sensitive in-memory data or cause a crash. Exploitation requires user interaction — specifically, a user must open the malicious file — and does not require any privileges. Multiple ZDI advisories (ZDI-25-1156 through ZDI-25-1161, and ZDI-26-058) document this and related vulnerabilities in the same file-parsing code path (CISA Advisory, ZDI-25-1159).

Impact

Successful exploitation can result in disclosure of sensitive information from process memory or a denial-of-service condition via application crash. In combination with related vulnerabilities in the same advisory (e.g., out-of-bounds write, use-after-free), an attacker could potentially achieve arbitrary code execution in the context of the current user process. Given DAQFactory's role in industrial data acquisition and HMI environments within critical manufacturing sectors, exploitation could disrupt operational technology (OT) processes or expose sensitive process data (CISA Advisory).

Exploitability

Multiple proof-of-concept advisories are publicly available through the Zero Day Initiative (ZDI-25-1156, ZDI-25-1157, ZDI-25-1158, ZDI-25-1159, ZDI-25-1160, ZDI-25-1161, and ZDI-26-058), published December 19, 2025, and February 3, 2026. CISA has stated that no known public exploitation specifically targeting this vulnerability has been reported, and the vulnerability is not exploitable remotely. The EPSS score is approximately 0.014% (very low probability of near-term exploitation). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA Advisory, ZDI-25-1161).

Exploitation steps

  1. Craft a malicious CTL file: Create a specially crafted AzeoTech DAQFactory .ctl project file that contains malformed data structures designed to trigger an out-of-bounds read during parsing.
  2. Deliver the file to the target: Use social engineering (e.g., phishing email, shared network drive, or supply chain compromise) to deliver the malicious .ctl file to a user running a vulnerable version of DAQFactory (≤20.7 Build 2555).
  3. Induce the victim to open the file: Convince the target user to open the malicious .ctl file within DAQFactory, triggering the vulnerable file-parsing code path.
  4. Trigger out-of-bounds read: The application reads data past the end of an allocated buffer, exposing memory contents that may include sensitive data (e.g., credentials, process values, or memory addresses useful for further exploitation).
  5. Leverage for further exploitation: Use disclosed memory information (e.g., heap or stack addresses) to bypass ASLR and chain with related vulnerabilities (e.g., CVE-2025-66590 out-of-bounds write) to achieve arbitrary code execution in the context of the DAQFactory process (CISA Advisory, ZDI-25-1159).

Indicators of compromise

  • File System: Presence of unexpected or externally sourced .ctl files in DAQFactory project directories, especially in locations writable by non-admin users.
  • Process: DAQFactory process (DAQFactory.exe) crashing unexpectedly or generating access violation errors; unusual child processes spawned by the DAQFactory process.
  • Logs: Windows Event Log entries showing application crashes (Event ID 1000) referencing DAQFactory.exe; Dr. Watson or Windows Error Reporting logs indicating memory access violations during CTL file parsing.
  • Network: Unexpected outbound network connections from the DAQFactory host following the opening of a .ctl file, which may indicate chained code execution exploitation (CISA Advisory).

Mitigation and workarounds

AzeoTech has released DAQFactory Release 21.1, which addresses CVE-2025-66589 and all related vulnerabilities in the advisory. Until patching is possible, CISA and AzeoTech recommend: (1) avoiding opening .ctl files from unknown or untrusted sources; (2) storing .ctl files in directories writable only by admin-level users; (3) operating in DAQFactory's "Safe Mode" when loading documents that have been outside of organizational control; (4) applying a document editing password to project files; and (5) isolating DAQFactory systems from the internet and business networks using firewalls and VPNs (CISA Advisory).

Community reactions

CISA published ICS Advisory ICSA-25-345-03 on December 11, 2025, and issued Update A on December 30, 2025, which refined the researcher acknowledgments and removed two duplicate CVEs. The vulnerabilities were reported to CISA by Michael Heinzl, Rocco Calvi (@TecR0c) of TecSecurity via Trend Zero Day Initiative, and Andrea Micalizzi (@rgod777) of Trend Zero Day Initiative. The Hawk-Eye threat intelligence blog included this CVE in its weekly threat landscape digest for Week 2 of 2026, indicating moderate community awareness (CISA Advisory).

Additional resources


SourceThis report was generated using AI

Related AzeoTech DAQFactory vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-12921HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoNoJun 25, 2026
CVE-2026-12390HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoNoJun 18, 2026
CVE-2025-66590HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025
CVE-2025-66589HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025
CVE-2025-66588HIGH8.4
  • AzeoTech DAQFactory logoAzeoTech DAQFactory
  • cpe:2.3:a:azeotech:daqfactory
NoYesDec 11, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management