NI LabVIEW Out-of-Bounds Read Vulnerability Allowing Information Disclosure or Arbitrary Code Execution

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in NI LabVIEW versions through 2025 Q1. This issue arises from improper bounds checking in the 'lvre!UDecStrToNum' function, potentially leading to information disclosure or arbitrary code execution. Successful exploitation requires an attacker to persuade a user to open a specially crafted virtual instrument (VI).

Impact

Exploitation of this vulnerability could result in unauthorized information disclosure or arbitrary code execution within the context of the user.

Remediation

Users are advised to upgrade to NI LabVIEW 2025 Q3 or later. For LabVIEW 2025 Q1, a patch is in progress. Instructions for downloading the updated version are available on the NI Software Downloads page.

Added: Jul 23, 2025, 4:25 PM
Updated: Jul 23, 2025, 4:25 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
4.4
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.