CVE-2025-64463

7.8

NI · LabVIEW

A memory corruption vulnerability in NI LabVIEW allows for information disclosure or arbitrary code execution when a user opens a specially crafted VI file.

Executive summary

An out of bounds read vulnerability in NI LabVIEW poses a critical risk of arbitrary code execution if a user is enticed to open a malicious VI file.

Vulnerability

This vulnerability is an out of bounds read flaw within the LVResource::DetachResource function. It occurs when the software parses a corrupted VI file, which can be triggered by an unauthenticated attacker if they can convince a user to open the malicious file.

Business impact

The potential for arbitrary code execution presents a significant security risk, as it could allow an attacker to gain full control over the affected system. Given the CVSS score of 7.8, this vulnerability is classified as High severity, indicating that it could lead to severe data compromise and unauthorized access to sensitive engineering environments. Organizations relying on LabVIEW for critical industrial or research workflows must treat this as a priority to prevent operational disruption and intellectual property theft.

Remediation

Immediate Action: Users must update to the latest patched version provided by NI as outlined in their security advisory.

Proactive Monitoring: Security teams should monitor for the introduction of unknown or untrusted VI files into the environment and review endpoint logs for suspicious process execution patterns.

Compensating Controls: Organizations should enforce strict file access policies and ensure that users are trained to avoid opening VI files from untrusted or external sources.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this vulnerability, combined with the potential for arbitrary code execution, necessitates immediate attention. Administrators should verify their current LabVIEW versions against the affected list and apply the vendor provided security updates without delay. Maintaining updated software remains the most effective defense against this and similar memory corruption risks.

More NI CVEs

Sources

Originally found and disclosed by Michael Heinzl working with CISA, per the CVE Program record.