Description
In AzeoTech DAQFactory release 20.7 (Build 2555), an Access of Resource Using Incompatible Type vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process.
Problem types
CWE-843 Access of Resource Using Incompatible Type ('Type Confusion')
Product status
Any version
Credits
Rocco Calvi (@TecR0c) with TecSecurity of Trend Zero Day Initiative
Andrea Micalizzi (@rgod777) of Trend Zero Day Initiative
References
www.cisa.gov/news-events/ics-advisories/icsa-25-345-03
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.