CVE-2025-66585

In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:azeotech:daqfactory:*:*:*:*:*:*:*:*

History

04 Jun 2026, 21:16

Type Values Removed Values Added
References
  • () https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-345-03.json -
Summary (en) In AzeoTech DAQFactory release 20.7 (Build 2555), a Use After Free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process. (en) In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.

02 Jan 2026, 20:04

Type Values Removed Values Added
CPE cpe:2.3:a:azeotech:daqfactory:*:*:*:*:*:*:*:*
First Time Azeotech daqfactory
Azeotech
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03 - () https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03 - Third Party Advisory, US Government Resource

11 Dec 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 21:15

Updated : 2026-06-04 21:16


NVD link : CVE-2025-66585

Mitre link : CVE-2025-66585

CVE.ORG link : CVE-2025-66585


JSON object : View

Products Affected

azeotech

  • daqfactory
CWE
CWE-416

Use After Free