NI LabVIEW Out-of-Bounds Read Vulnerability in Font Manager Allowing Information Disclosure or Arbitrary Code Execution

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in NI LabVIEW, specifically in the font manager component. This issue arises from improper bounds checking, which may lead to information disclosure or arbitrary code execution. Successful exploitation requires an attacker to persuade a user to open a specially crafted virtual instrument (VI). This vulnerability affects NI LabVIEW versions 2025 Q1 and prior.

Impact

Exploitation of this vulnerability could result in unauthorized information disclosure or arbitrary code execution within the application.

Remediation

Users are advised to upgrade to NI LabVIEW 2025 Q3 or later. For LabVIEW 2025 Q1, a patch is in progress. Instructions for downloading the updated version are available on the NI Software Downloads page.

Added: Jul 23, 2025, 4:22 PM
Updated: Jul 23, 2025, 4:22 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
2.5
exploitability
4.0
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.