CVE-2025-6033

7.8

NI · Circuit Design Suite

NI Circuit Design Suite contains an out of bounds write vulnerability in SymbolEditor that could allow arbitrary code execution or information disclosure via a crafted .sym file.

Executive summary

A memory corruption vulnerability in NI Circuit Design Suite permits local attackers to achieve arbitrary code execution by enticing a user to open a malicious file.

Vulnerability

This vulnerability is an out of bounds write (CWE-787) occurring within the XML_Serialize function of the SymbolEditor component. Exploitation requires user interaction, specifically the opening of a specially crafted .sym file, and the attacker does not require prior authentication.

Business impact

The ability to trigger arbitrary code execution poses a severe risk to organizational integrity, as it allows an attacker to execute commands with the privileges of the logged in user. This could lead to full system compromise, unauthorized data access, and the potential for lateral movement within the network. Given the CVSS score of 7.8, this high severity flaw warrants immediate attention to prevent operational disruption.

Remediation

Immediate Action: Users should refer to the official NI security advisory for the latest available patches and apply all relevant updates to the Circuit Design Suite immediately.

Proactive Monitoring: Security teams should monitor endpoint activity for unexpected child processes spawned by the Circuit Design Suite application and review file system logs for the importation of suspicious .sym files.

Compensating Controls: Implement strict application control policies to prevent the execution of unauthorized software and ensure that users are trained to handle files from untrusted sources with extreme caution.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Due to the potential for arbitrary code execution, this vulnerability represents a significant security risk to any environment utilizing NI Circuit Design Suite. Organizations should prioritize the identification of all affected installations and ensure they are updated to a secure version as soon as the vendor makes a patch available.

More NI CVEs

Sources

Originally found and disclosed by Michael Heinzl working with CISA, per the CVE Program record.