CVE-2026-0957
7.8Digilent · DASYLab
Digilent DASYLab contains a memory corruption vulnerability caused by an out-of-bounds write when processing specially crafted files, potentially leading to arbitrary code execution.
Executive summary
A memory corruption flaw in Digilent DASYLab poses a high risk of arbitrary code execution if a user is tricked into opening a malicious file.
Vulnerability
This vulnerability is a memory corruption issue triggered by an out-of-bounds write when the software parses a corrupted file. Successful exploitation requires a local user to interact with the application by opening a specially crafted file, as indicated by the user interaction requirement in the CVSS vector.
Business impact
The vulnerability carries a CVSS score of 7.8, classifying it as a High severity threat. Successful exploitation could lead to full system compromise or arbitrary code execution, resulting in significant potential for data theft, loss of intellectual property, or operational disruption within research and engineering environments.
Remediation
Immediate Action: Monitor the official National Instruments security portal for the release of a patched version of DASYLab and apply the update immediately upon availability.
Proactive Monitoring: Implement endpoint security solutions to monitor for unusual process behavior or crashes associated with DASYLab when opening untrusted files.
Compensating Controls: Advise users to exercise extreme caution and verify the source of all files before opening them in DASYLab, as the exploit relies on social engineering to initiate the attack.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Given the potential for arbitrary code execution, this vulnerability represents a severe risk to any environment utilizing DASYLab. Administrators must prioritize the deployment of vendor-supplied patches as soon as they are released and enforce strict policies regarding the handling of files from untrusted sources to mitigate the risk until remediation is complete.
More Digilent CVEs
Sources
Originally found and disclosed by Rocco Calvi (@TecR0c) with TecSecurity, with Trend Micro Zero Day Initiative (coordinator), per the CVE Program record.