NI LabVIEW
cpe:2.3:a:ni:labview:*:*:*:*:*:*:*
- 2025 Q1
- 2025
A vulnerability allowing out-of-bounds read has been identified in NI LabVIEW, specifically in the font manager component. This issue arises from improper bounds checking, which may lead to information disclosure or arbitrary code execution. Successful exploitation requires an attacker to persuade a user to open a specially crafted virtual instrument (VI). This vulnerability affects NI LabVIEW versions 2025 Q1 and prior.
Exploitation of this vulnerability could result in unauthorized information disclosure or arbitrary code execution within the application.
Users are advised to upgrade to NI LabVIEW 2025 Q3 or later. For LabVIEW 2025 Q1, a patch is in progress. Instructions for downloading the updated version are available on the NI Software Downloads page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.