CVE-2026-0955
7.8Digilent · DASYLab
Digilent DASYLab contains an out-of-bounds read vulnerability that may lead to information disclosure or arbitrary code execution when processing a specially crafted file.
Executive summary
A critical memory corruption vulnerability in Digilent DASYLab could allow an attacker to achieve arbitrary code execution by tricking a user into opening a malicious file.
Vulnerability
This is an out-of-bounds read vulnerability (CWE-125) triggered when the software parses a corrupted file. Successful exploitation requires user interaction to open a malicious file, but it does not require prior authentication.
Business impact
The potential for arbitrary code execution poses a significant threat to organizational security, as it could allow an attacker to gain full control over a compromised system. With a CVSS score of 7.8, this high-severity flaw may lead to data theft, system instability, or the installation of persistent malware. Organizations relying on DASYLab for critical operations face substantial risk until the vulnerability is addressed.
Remediation
Immediate Action: Review the official security advisory from National Instruments (NI) to determine if a patch has been released for your specific environment and apply it immediately.
Proactive Monitoring: Monitor system logs for unusual application crashes or file access patterns that deviate from standard operational behavior.
Compensating Controls: Advise users to exercise caution when opening files from untrusted sources and implement endpoint security solutions that scan files for malicious content before execution.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a significant risk to affected environments. Organizations should prioritize monitoring vendor communications for patch availability and ensure that users are aware of the risks associated with opening untrusted files. Apply all security updates immediately upon release to mitigate the risk of exploitation.
More Digilent CVEs
Sources
Originally found and disclosed by Rocco Calvi (@TecR0c) with TecSecurity, with Trend Micro Zero Day Initiative (coordinator), per the CVE Program record.