PT-2025-52243 · National Instruments · Ni Labview

·

CVE-2025-64469

·

Published

2025-12-18

·

Updated

2025-12-24

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NI LabVIEW versions prior to 2025 Q3 (25.3)
Description A stack-based buffer overflow exists in the LVResFile::FindRsrcListEntry() function when parsing a corrupted VI file. Successful exploitation requires a user to open a specially crafted VI, potentially leading to information disclosure or arbitrary code execution.
Recommendations Update to NI LabVIEW 2025 Q3 (25.3) or later.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64469

Affected Products

Ni Labview