CVE-2025-2633
7.8NI · LabVIEW
An out of bounds read vulnerability in NI LabVIEW, specifically within the lvre!UDecStrToNum function, may allow for information disclosure or arbitrary code execution.
Executive summary
A critical out of bounds read vulnerability in NI LabVIEW could allow an attacker to achieve arbitrary code execution by convincing a user to open a specially crafted VI file.
Vulnerability
This vulnerability is caused by improper bounds checking within the lvre!UDecStrToNum function. An attacker can trigger this flaw by tricking a user into opening a malicious Virtual Instrument (VI) file, requiring user interaction to execute.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational systems, as it could allow an attacker to gain full control over a compromised host. With a CVSS score of 7.8, this high severity flaw could lead to significant data breaches, loss of system integrity, and operational disruption if left unpatched.
Remediation
Immediate Action: Update all installations of NI LabVIEW to version 25.3.0 or the latest available patched release provided by NI.
Proactive Monitoring: Monitor system logs for unusual file activity or execution patterns associated with VI files opened by users.
Compensating Controls: Implement strict email and file transfer filtering policies to prevent users from opening untrusted or unsolicited VI files from unknown sources.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a significant security risk to any environment utilizing NI LabVIEW. Administrators should prioritize the deployment of the vendor-supplied security updates to all affected systems. Failure to patch these instances could expose the organization to remote compromise should a user be successfully social-engineered into opening a malicious file.
More NI CVEs
Sources
Originally found and disclosed by Michael Heinzl working with CISA, per the CVE Program record.