CVE-2025-57775

7.8

Digilent · DASYLab

A heap-based buffer overflow in Digilent DASYLab allows for arbitrary code execution when a user opens a specially crafted DSB file.

Executive summary

A heap-based buffer overflow vulnerability in Digilent DASYLab poses a high risk, as it may allow an attacker to achieve arbitrary code execution via a malicious DSB file.

Vulnerability

This is a heap-based buffer overflow caused by improper bounds checking during the parsing of DSB files. Successful exploitation requires an unauthenticated attacker to convince a user to open a specially crafted file, leveraging local interaction to trigger the flaw.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its high potential for severe impact despite the requirement for user interaction. Successful exploitation allows for arbitrary code execution, which could lead to full system compromise, loss of data integrity, and unauthorized access to sensitive information within the environment where the software is deployed.

Remediation

Immediate Action: Review the official security advisory from National Instruments to determine if a patch is available for your specific deployment. If no patch is currently available, restrict the opening of untrusted DSB files from unknown sources.

Proactive Monitoring: Monitor system logs for unusual application crashes or unexpected spikes in CPU usage that occur when users interact with DSB files.

Compensating Controls: Ensure that endpoint protection software is configured to scan incoming files for malicious patterns and enforce strict file execution policies to prevent unauthorized code from running.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability represents a significant security risk to any organization utilizing Digilent DASYLab. Administrators should prioritize monitoring vendor communications for the release of a security patch and ensure that users are trained to exercise caution when handling files from external or untrusted sources until a permanent fix is verified and applied.

More Digilent CVEs

Sources

Originally found and disclosed by kimiya working with Trend Micro Zero Day Initiative, per the CVE Program record.