CVE-2026-0956
7.8Digilent · DASYLab
Digilent DASYLab contains an out-of-bounds read vulnerability triggered by opening a specially crafted file, potentially leading to information disclosure or arbitrary code execution.
Executive summary
A memory corruption vulnerability in Digilent DASYLab allows for potential remote code execution if a user is tricked into opening a malicious file.
Vulnerability
This vulnerability is an out-of-bounds read (CWE-125) that occurs when the software processes a corrupted file. Successful exploitation requires a local user to interact with a malicious file, and the attacker does not require prior authentication.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational security, as it allows attackers to run unauthorized commands on the host system. With a CVSS score of 7.8, this vulnerability is classified as High severity. Successful exploitation could lead to full system compromise, loss of data integrity, and unauthorized access to sensitive information within the user environment.
Remediation
Immediate Action: Review the vendor advisory provided by National Instruments and check for available software patches or security updates for DASYLab.
Proactive Monitoring: Monitor system logs for unusual application crashes or errors associated with file processing tasks.
Compensating Controls: Advise users to exercise caution when opening files from untrusted sources and employ endpoint protection software to scan files for malicious signatures before execution.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a significant risk to workstations running DASYLab. Administrators should prioritize identifying all instances of the software within their infrastructure and apply security updates as soon as they are made available by the vendor. Users must be warned against opening unexpected or untrusted files in the application until a patch is verified and deployed.
More Digilent CVEs
Sources
Originally found and disclosed by Rocco Calvi (@TecR0c) with TecSecurity, with Trend Micro Zero Day Initiative (coordinator), per the CVE Program record.