CVE-2025-6033
7.8NI · Circuit Design Suite
NI Circuit Design Suite contains an out of bounds write vulnerability in SymbolEditor that could allow arbitrary code execution or information disclosure via a crafted .sym file.
Executive summary
A memory corruption vulnerability in NI Circuit Design Suite permits local attackers to achieve arbitrary code execution by enticing a user to open a malicious file.
Vulnerability
This vulnerability is an out of bounds write (CWE-787) occurring within the XML_Serialize function of the SymbolEditor component. Exploitation requires user interaction, specifically the opening of a specially crafted .sym file, and the attacker does not require prior authentication.
Business impact
The ability to trigger arbitrary code execution poses a severe risk to organizational integrity, as it allows an attacker to execute commands with the privileges of the logged in user. This could lead to full system compromise, unauthorized data access, and the potential for lateral movement within the network. Given the CVSS score of 7.8, this high severity flaw warrants immediate attention to prevent operational disruption.
Remediation
Immediate Action: Users should refer to the official NI security advisory for the latest available patches and apply all relevant updates to the Circuit Design Suite immediately.
Proactive Monitoring: Security teams should monitor endpoint activity for unexpected child processes spawned by the Circuit Design Suite application and review file system logs for the importation of suspicious .sym files.
Compensating Controls: Implement strict application control policies to prevent the execution of unauthorized software and ensure that users are trained to handle files from untrusted sources with extreme caution.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the potential for arbitrary code execution, this vulnerability represents a significant security risk to any environment utilizing NI Circuit Design Suite. Organizations should prioritize the identification of all affected installations and ensure they are updated to a secure version as soon as the vendor makes a patch available.
More NI CVEs
Sources
Originally found and disclosed by Michael Heinzl working with CISA, per the CVE Program record.