VYPR
advisoryPublished Jul 23, 2026· 2 sources

AzeoTech DAQFactory Vulnerability Allows Remote Code Execution via CTL File Parsing

A use-after-free vulnerability in AzeoTech DAQFactory's CTL file parsing, tracked as CVE-2026-12921, allows remote attackers to execute arbitrary code with user interaction.

A critical use-after-free vulnerability has been identified in AzeoTech's DAQFactory software, enabling remote attackers to execute arbitrary code on affected systems. The vulnerability, cataloged as CVE-2026-12921, carries a CVSS score of 7.8 and requires a user to interact with a malicious file or webpage for exploitation.

The core of the issue lies within the software's handling of CTL files. Specifically, the DAQFactory fails to properly validate the existence of an object before attempting to perform operations on it. This oversight allows an attacker to manipulate the program's state, leading to a use-after-free condition that can be leveraged for arbitrary code execution within the context of the running process.

Exploitation of this vulnerability necessitates that a user either opens a specially crafted CTL file or visits a malicious webpage that triggers the vulnerable code path. Once exploited, an attacker could gain control over the affected DAQFactory installation, potentially leading to further system compromise or data exfiltration. The reliance on user interaction, however, provides a degree of mitigation if users are trained to be cautious about opening unknown files or visiting suspicious links.

AzeoTech has acknowledged the vulnerability and has released an update to address the flaw. Security advisories, including one from CISA (ICSA-26-169-02), provide further details on the vulnerability and recommend immediate patching. The disclosure timeline indicates that the vulnerability was reported to the vendor on March 2, 2026, with a coordinated public release of the advisory on July 23, 2026.

The vulnerability was discovered and reported by Rocco Calvi of TecSecurity. This finding highlights the ongoing risks associated with industrial control system (ICS) software, where vulnerabilities can have significant operational and safety implications. The use-after-free flaw is a common type of memory corruption bug that often leads to exploitable conditions.

Users and administrators of AzeoTech DAQFactory are strongly advised to apply the available security updates as soon as possible to mitigate the risk of exploitation. Organizations should also review their security practices, including user awareness training regarding phishing and malicious file handling, to further bolster their defenses against such threats.

This vulnerability underscores the importance of regular security audits and timely patching for all software, especially in critical infrastructure environments where the impact of a breach can be severe. The proactive disclosure by Zero Day Initiative and the vendor's swift response are crucial steps in protecting users from potential attacks.

This updated advisory from the Zero Day Initiative (ZDI) assigns CVE-2026-12390 to the AzeoTech DAQFactory CTL file parsing vulnerability, noting a CVSS score of 7.8. The advisory also includes a link to a CISA ICS advisory (ICSA-26-169-02) which provides further details on the vulnerability and mitigation steps. The disclosure timeline indicates a coordinated public release on July 23, 2026, with an update to the advisory on the same day.

Synthesized by Vypr AI