CVE-2025-2634
7.8NI · LabVIEW
A critical out of bounds read vulnerability exists in NI LabVIEW fontmgr, potentially allowing arbitrary code execution if a user opens a specially crafted VI file.
Executive summary
NI LabVIEW contains a critical out of bounds read vulnerability that may lead to arbitrary code execution if a victim is induced to open a malicious file.
Vulnerability
This vulnerability is an out of bounds read (CWE-1285) within the fontmgr component, which can be triggered when an unauthenticated user is convinced to open a specially crafted VI file.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational security, as it could allow attackers to gain full control over the affected system. Given the CVSS score of 7.8, this vulnerability is classified as High, reflecting the significant danger of system compromise if the attack vector is successfully executed via social engineering.
Remediation
Immediate Action: Update all instances of NI LabVIEW to the latest patched version as specified by the vendor security advisory.
Proactive Monitoring: Monitor system logs for unusual file execution patterns or unexpected crashes associated with the LabVIEW application.
Compensating Controls: Advise users to exercise extreme caution when opening unknown or untrusted VI files received from external sources.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the potential for arbitrary code execution, this vulnerability represents a significant threat to workstation integrity. Administrators should prioritize the deployment of the vendor provided updates to all affected LabVIEW installations to eliminate this risk entirely.
More NI CVEs
Sources
Originally found and disclosed by Michael Heinzl working with CISA, per the CVE Program record.