PatchSiren cyber security CVE debrief
CVE-2025-66590 AzeoTech CVE debrief
CVE-2025-66590 is a high-severity out-of-bounds write vulnerability in AzeoTech DAQFactory release 20.7 (Build 2555), published by CISA on December 11, 2025, with subsequent modifications through January 12, 2026. The vulnerability allows an attacker to cause the program to write data past the end of an allocated memory buffer, potentially leading to arbitrary code execution or system crash. The CVSS 3.1 score of 7.8 reflects local attack vector, low attack complexity, no privileges required, and user interaction required, with high impacts to confidentiality, integrity, and availability. AzeoTech has released DAQFactory Release 21.1 as a vendor fix. CISA recommends defense-in-depth measures including avoiding documents from untrusted sources, storing .ctl files in admin-writeable folders only, operating in Safe Mode when loading untrusted documents, and applying document editing passwords.
- Vendor
- AzeoTech
- Product
- DAQFactory
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-11
- Original CVE updated
- 2026-10-07
- Advisory published
- 2025-12-11
- Advisory updated
- 2026-10-07
Who should care
Organizations operating AzeoTech DAQFactory in industrial control system environments, particularly those processing untrusted document files or with multi-user access to .ctl configuration files. Asset owners in manufacturing, process control, and building automation sectors using DAQFactory for data acquisition and supervisory control should prioritize patching.
Technical summary
The vulnerability exists in DAQFactory release 20.7 (Build 2555) where an out-of-bounds write condition can be triggered, causing writes beyond allocated buffer boundaries. This memory safety defect may result in arbitrary code execution within the context of the application or cause denial of service through system crash. The attack requires local access and user interaction, suggesting exploitation via malicious document files.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade to DAQFactory Release 21.1 per vendor fix guidance.
- Avoid opening documents from unknown or untrusted sources.
- Store .ctl files in directories with admin-only write permissions.
- Enable Safe Mode when loading documents that have been outside organizational control.
- Apply document editing passwords to protect document integrity.
- Review CISA ICS recommended practices for additional defense-in-depth strategies.
Evidence notes
Vendor and product identification derived from CSAF product tree with high confidence. Remediation guidance extracted from CSAF remediations section. CVSS vector confirmed via source references.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-66590 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-66590
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-66590 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-66590
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-345-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-345-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.