CVE-2025-57777

7.8

Digilent · DASYLab

Digilent DASYLab contains an out of bounds write vulnerability in displ2.dll, which may allow an attacker to achieve arbitrary code execution by tricking a user into opening a malicious DSB file.

Executive summary

A critical out of bounds write vulnerability in Digilent DASYLab allows for arbitrary code execution through the processing of specially crafted DSB files.

Vulnerability

The vulnerability is an out of bounds write (CWE-1285) located in the displ2.dll component, triggered during the parsing of DSB files. Exploitation requires user interaction, as an attacker must convince a victim to open a malicious file.

Business impact

This vulnerability poses a significant risk to organizational integrity, as successful exploitation enables arbitrary code execution on the host system. Given the CVSS score of 7.8, which reflects a High severity rating, potential consequences include full system compromise, unauthorized data access, and the potential for lateral movement within the network.

Remediation

Immediate Action: Users should refer to the official National Instruments security advisory to determine if a patch is available or if specific configuration changes are required to mitigate the file parsing risk.

Proactive Monitoring: Security teams should monitor endpoint logs for unusual processes spawned by DASYLab or unexpected file system activity originating from the application.

Compensating Controls: Implement strict file access policies and ensure that users do not open untrusted DSB files from unknown or unverified sources.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Due to the severity of the potential impact, all systems running Digilent DASYLab should be considered at risk. Administrators must prioritize identifying all instances of this software within the environment and apply vendor-supplied updates as soon as they are released to neutralize the threat of arbitrary code execution.

More Digilent CVEs

Sources

Originally found and disclosed by kimiya working with Trend Micro Zero Day Initiative, per the CVE Program record.