CVE-2025-57776

7.8

Digilent · DASYLab

Digilent DASYLab suffers from an out of bounds write vulnerability during the parsing of DSB files, which can lead to arbitrary code execution.

Executive summary

An out of bounds write vulnerability in Digilent DASYLab poses a critical risk of arbitrary code execution to users who open maliciously crafted DSB files.

Vulnerability

This vulnerability is caused by improper validation of specified offsets during the parsing of DSB files (CWE-1285). An attacker can trigger this flaw by convincing a user to open a specially crafted file, requiring no authentication from the attacker.

Business impact

The potential for arbitrary code execution creates a significant risk of system compromise, data exfiltration, or the installation of persistent malicious software. With a CVSS score of 7.8, this vulnerability is classified as High, reflecting the severe impact on system integrity and availability if an attacker successfully executes code in the context of the user.

Remediation

Immediate Action: Monitor the official National Instruments security update portal for the release of a patch and apply it to all DASYLab installations immediately upon availability.

Proactive Monitoring: Review system and application logs for unusual file handling patterns or unexpected crashes occurring during the opening of DSB files.

Compensating Controls: Implement strict user training to prevent the opening of untrusted or unexpected DSB files, and utilize endpoint detection and response tools to monitor for suspicious process spawns originating from DASYLab.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the capability for arbitrary code execution, this vulnerability represents a high-severity threat to any environment utilizing Digilent DASYLab. Administrators should prioritize the application of vendor-supplied patches as soon as they are published and restrict the processing of untrusted DSB files to minimize the attack surface.

More Digilent CVEs

Sources

Originally found and disclosed by kimiya working with Trend Micro Zero Day Initiative, per the CVE Program record.