CVE-2025-64465

7.8

NI · LabVIEW

NI LabVIEW contains an out-of-bounds read vulnerability in the lvre!DataSizeTDR function, which may allow for information disclosure or arbitrary code execution via a specially crafted VI file.

Executive summary

A critical out-of-bounds read vulnerability in NI LabVIEW could allow an attacker to achieve arbitrary code execution by tricking a user into opening a malicious VI file.

Vulnerability

This vulnerability is an out-of-bounds read (CWE-125) located within the lvre!DataSizeTDR function, triggered when the application parses a corrupted Virtual Instrument (VI) file. Exploitation requires user interaction, as an attacker must convince a victim to open a specially crafted file.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational systems, as successful exploitation could lead to full system compromise or sensitive information disclosure. With a CVSS score of 7.8, this high-severity flaw represents a significant threat to internal environments, particularly in engineering or industrial settings where LabVIEW is utilized.

Remediation

Immediate Action: Update all instances of NI LabVIEW to the latest patched version provided by the vendor. Refer to the official NI security advisory for specific versioning details and download links.

Proactive Monitoring: Monitor endpoint activity for instances of LabVIEW crashing or executing unexpected child processes, which may indicate an attempt to leverage this memory corruption flaw.

Compensating Controls: Implement strict email filtering and endpoint protection policies to block or scan suspicious VI files before they reach end-user workstations.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for code execution, it is imperative that organizations audit their software inventory to identify affected LabVIEW installations. Security teams should prioritize patching as the primary defense, as this vulnerability cannot be fully mitigated by network-level controls alone. Ensure that all users are cautioned against opening untrusted project files from unknown sources.

More NI CVEs

Sources

Originally found and disclosed by Michael Heinzl working with CISA, per the CVE Program record.