CVE-2025-6034

7.8

NI · Circuit Design Suite

A memory corruption vulnerability in the NI Circuit Design Suite SymbolEditor allows for potential arbitrary code execution or information disclosure via a crafted .sym file.

Executive summary

A critical memory corruption vulnerability in NI Circuit Design Suite exposes users to potential arbitrary code execution when opening malicious files.

Vulnerability

This vulnerability is an out-of-bounds read error (CWE-125) located within the DefaultFontOptions function of the SymbolEditor. It requires a local, unauthenticated attacker to convince a user to open a specially crafted .sym file to trigger the exploit.

Business impact

Successful exploitation of this flaw could lead to unauthorized information disclosure or the execution of arbitrary code with the privileges of the logged-in user. Given the CVSS score of 7.8, this represents a high-severity risk that could result in full system compromise or the exfiltration of sensitive design data, significantly impacting both operational integrity and intellectual property security.

Remediation

Immediate Action: Review the official NI security advisory for specific patch availability and apply all recommended updates to versions beyond 14.3.1 as soon as they are provided.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected crashes occurring immediately after users open design files.

Compensating Controls: Restrict file permissions and implement strict endpoint protection policies to prevent users from opening untrusted .sym files from external or unverified sources.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing NI Circuit Design Suite should prioritize identifying all instances of version 14.3.1 and earlier within their environment. Since this vulnerability requires user interaction, user awareness training regarding the handling of untrusted design files is strongly recommended alongside the application of vendor-supplied patches once they are officially released.

More NI CVEs

Sources

Originally found and disclosed by Michael Heinzl working with CISA, per the CVE Program record.