CVE-2026-0954
7.8Digilent · DASYLab
Digilent DASYLab contains an out-of-bounds write vulnerability triggered by loading a malformed .DSB file, which may lead to arbitrary code execution.
Executive summary
A critical memory corruption vulnerability in Digilent DASYLab allows an attacker to execute arbitrary code or disclose sensitive information via a specially crafted .DSB file.
Vulnerability
This is an out-of-bounds write (CWE-787) vulnerability occurring when the software parses a corrupted .DSB file. Exploitation requires an unauthenticated attacker to convince a user to open a malicious file, representing a local attack vector with user interaction.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational security, including unauthorized system access and data exfiltration. With a CVSS score of 7.8, this high-severity vulnerability could lead to total system compromise if an attacker successfully executes code with the privileges of the logged-in user.
Remediation
Immediate Action: Review the official NI security advisory for the latest available patches and apply them to all instances of DASYLab.
Proactive Monitoring: Monitor endpoint activity for unexpected process execution or memory-related crashes associated with the DASYLab application.
Compensating Controls: Implement strict file-handling policies and utilize endpoint detection and response tools to scan incoming files for anomalies before they are opened by users.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability should be treated with high urgency. Administrators are advised to restrict the opening of untrusted .DSB files and prioritize the installation of vendor-provided updates as soon as they become available to mitigate the risk of system compromise.
More Digilent CVEs
Sources
Originally found and disclosed by Anonymous working with Trend Micro Zero Day Initiative, per the CVE Program record.