CVE-2025-57774

7.8

Digilent · DASYLab

Digilent DASYLab is susceptible to an out of bounds write vulnerability when parsing DSB files, which may allow an attacker to achieve arbitrary code execution via a specially crafted file.

Executive summary

A critical out of bounds write vulnerability in Digilent DASYLab poses a significant risk of arbitrary code execution if a user opens a malicious DSB file.

Vulnerability

This vulnerability involves improper validation of specified indexes or offsets during the parsing of DSB files (CWE-1285). The attack requires user interaction, where an unauthenticated attacker must convince a user to open a specially crafted file to trigger the memory corruption.

Business impact

The potential for arbitrary code execution creates a severe security risk, as successful exploitation could lead to full system compromise, loss of data integrity, and unauthorized control over the affected workstation. With a CVSS score of 7.8, this vulnerability is classified as High severity and necessitates immediate attention to prevent potential lateral movement or persistent malware installation within the operational environment.

Remediation

Immediate Action: Review the official National Instruments security advisory to determine if a patch has been released for your specific version of DASYLab and apply it immediately.

Proactive Monitoring: Monitor file system access logs for unusual activity associated with DSB file parsing and restrict the execution of untrusted files from external sources.

Compensating Controls: Ensure that endpoint protection software is configured to scan files upon access and implement robust user awareness training to prevent the opening of suspicious or unsolicited data files.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant threat to system security. Users must exercise extreme caution when handling DSB files from untrusted sources and monitor the Digilent and National Instruments security portals for the latest patches or configuration guidance. Applying the vendor update as soon as it becomes available is the only effective way to fully mitigate this risk.

More Digilent CVEs

Sources

Originally found and disclosed by kimiya working with Trend Micro Zero Day Initiative, per the CVE Program record.