service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2011-3460
http://www.us-cert.gov/control_systems/pdf/ICS-ALERT-11-256-04.pdf