CVE-2025-9189
7.8Digilent · DASYLab
Digilent DASYLab contains an out of bounds write vulnerability during the parsing of DSB files, which may lead to arbitrary code execution if a user opens a specially crafted file.
Executive summary
A critical out of bounds write vulnerability in Digilent DASYLab could allow an attacker to achieve arbitrary code execution through the use of a malicious DSB file.
Vulnerability
This is an out of bounds write vulnerability (CWE-1285) caused by improper validation of input offsets when parsing DSB files. The vulnerability requires no authentication, but successful exploitation requires a user to interact with a specially crafted file.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational security, as it allows attackers to gain control over affected systems. With a CVSS score of 7.8, this vulnerability is classified as High severity, indicating that a successful compromise could lead to significant data loss, unauthorized system access, and operational disruption.
Remediation
Immediate Action: Review the official security advisory from National Instruments (NI) and apply available updates or vendor-recommended workarounds immediately.
Proactive Monitoring: Monitor system logs for unusual application crashes or file access patterns involving DASYLab and DSB file types.
Compensating Controls: Implement strict file access controls and utilize endpoint protection software to scan incoming files for malicious content before they are opened by users.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a significant risk to any environment utilizing Digilent DASYLab. Administrators should prioritize the identification of all instances of this software within their infrastructure and monitor the vendor support portal for the release of a definitive patch. Until a patch is confirmed, enforcing user awareness regarding the risks of opening untrusted DSB files is essential to mitigate the threat.
More Digilent CVEs
Sources
Originally found and disclosed by kimiya working with Trend Micro Zero Day Initiative, per the CVE Program record.