CVE-2025-57778

7.8

Digilent · DASYLab

Digilent DASYLab is vulnerable to an out of bounds write flaw during DSB file parsing, which can be triggered by a user opening a malicious file to achieve arbitrary code execution.

Executive summary

A critical out of bounds write vulnerability in Digilent DASYLab allows for arbitrary code execution if a user is enticed to open a specially crafted DSB file.

Vulnerability

This vulnerability involves improper validation of specified index, position, or offset in input when parsing DSB files. It requires no authentication, but does necessitate user interaction to execute the malicious file.

Business impact

The potential for arbitrary code execution presents a significant risk to organizational integrity and data confidentiality. Given the CVSS score of 7.8, this vulnerability is classified as High severity, as successful exploitation could grant an attacker full control over the victim's local machine, potentially leading to total system compromise.

Remediation

Immediate Action: Monitor the official National Instruments (NI) security advisory page for the release of a patch and apply it immediately upon availability.

Proactive Monitoring: Implement endpoint detection and response (EDR) solutions to monitor for suspicious file-parsing behavior or unexpected child processes spawned by DASYLab.

Compensating Controls: Restrict the ability of users to open untrusted or externally sourced DSB files until a patch is applied, and utilize application allowlisting to prevent unauthorized code execution.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The risk posed by arbitrary code execution necessitates immediate attention from security administrators. While no patch is currently available, you should prioritize restricting access to untrusted DSB files and maintain vigilance for vendor updates on the provided NI security portal.

More Digilent CVEs

Sources

Originally found and disclosed by kimiya working with Trend Micro Zero Day Initiative, per the CVE Program record.