---
id: CVE-2025-66585
title: >-
  In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free
  vulnerability can be exploited to cause memory corruption while parsing
  specially crafted .ctl files
summary: >-
  In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free
  vulnerability can be exploited to cause memory corruption while parsing
  specially crafted .ctl files. This could allow an attacker to execute code in
  the context of the c…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: azeotech
product: daqfactory
affected:
  - daqfactory < 21.1
patched:
  - daqfactory 21.1
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66585'
references:
  - url: >-
      https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2025/icsa-25-345-03.json
    label: ics-cert@hq.dhs.gov
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03'
    label: ics-cert@hq.dhs.gov
tags:
  - nvd
epss: 0.00237
epssPercentile: 0.13486
ingestedAt: '2026-10-07T20:46:46.865Z'
---

## Overview

In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.

## Affected

- `daqfactory < 21.1`

## Remediation

Upgrade past the affected range:

- `daqfactory 21.1`
