CVE-2025-2633

7.8

NI · LabVIEW

An out of bounds read vulnerability in NI LabVIEW, specifically within the lvre!UDecStrToNum function, may allow for information disclosure or arbitrary code execution.

Executive summary

A critical out of bounds read vulnerability in NI LabVIEW could allow an attacker to achieve arbitrary code execution by convincing a user to open a specially crafted VI file.

Vulnerability

This vulnerability is caused by improper bounds checking within the lvre!UDecStrToNum function. An attacker can trigger this flaw by tricking a user into opening a malicious Virtual Instrument (VI) file, requiring user interaction to execute.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational systems, as it could allow an attacker to gain full control over a compromised host. With a CVSS score of 7.8, this high severity flaw could lead to significant data breaches, loss of system integrity, and operational disruption if left unpatched.

Remediation

Immediate Action: Update all installations of NI LabVIEW to version 25.3.0 or the latest available patched release provided by NI.

Proactive Monitoring: Monitor system logs for unusual file activity or execution patterns associated with VI files opened by users.

Compensating Controls: Implement strict email and file transfer filtering policies to prevent users from opening untrusted or unsolicited VI files from unknown sources.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant security risk to any environment utilizing NI LabVIEW. Administrators should prioritize the deployment of the vendor-supplied security updates to all affected systems. Failure to patch these instances could expose the organization to remote compromise should a user be successfully social-engineered into opening a malicious file.

More NI CVEs

Sources

Originally found and disclosed by Michael Heinzl working with CISA, per the CVE Program record.