There is an out of bounds read vulnerability in NI LabVIEW in lvre!ExecPostedProcRecPost() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
References
| Link | Resource |
|---|---|
| https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/multiple-memory-corruption-vulnerabilities-in-ni-labview.html | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-12-18 15:15
Updated : 2025-12-24 15:11
NVD link : CVE-2025-64466
Mitre link : CVE-2025-64466
CVE.ORG link : CVE-2025-64466
JSON object : View
Products Affected
ni
- labview
CWE
CWE-125
Out-of-bounds Read
