CVE-2025-64461

7.8

NI · LabVIEW

NI LabVIEW contains an out of bounds write vulnerability in the mgocre_SH_25_3!RevBL function, allowing for potential arbitrary code execution when processing a maliciously crafted VI file.

Executive summary

A critical out of bounds write vulnerability in NI LabVIEW allows for arbitrary code execution if a user is tricked into opening a specially crafted VI file.

Vulnerability

This is an out of bounds write vulnerability (CWE-787) occurring during the parsing of corrupted VI files. The vulnerability requires user interaction, specifically the opening of a malicious file by an unauthenticated user.

Business impact

Successful exploitation of this memory corruption flaw can lead to arbitrary code execution or information disclosure on the host system. With a CVSS score of 7.8, this vulnerability represents a high risk to operational integrity, as it could allow an attacker to gain control over engineering workstations or development environments, potentially leading to the compromise of proprietary intellectual property or the disruption of industrial processes.

Remediation

Immediate Action: Review the official NI security advisory and apply the necessary patches or software updates as soon as they are made available by the vendor.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected crashes occurring specifically when LabVIEW is parsing project files.

Compensating Controls: Implement strict file access policies and user awareness training to prevent the opening of untrusted or unsolicited VI files from unknown sources.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability poses a significant threat to environments utilizing NI LabVIEW. Administrators should prioritize identifying all instances of the affected software within their infrastructure and prepare to deploy vendor-supplied updates immediately upon release to mitigate the risk of system compromise.

More NI CVEs

Sources

Originally found and disclosed by Michael Heinzl working with CISA, per the CVE Program record.