Out of Bounds Read Vulnerability in NI LabVIEW Software
CVE-2025-2633

7.3HIGH

Key Information:

Vendor

Ni

Status
Vendor
CVE Published:
23 July 2025

What is CVE-2025-2633?

An out of bounds read vulnerability has been identified in NI LabVIEW, specifically within the function lvre!UDecStrToNum. This vulnerability arises from inadequate bounds checking, which can lead to potential information disclosure or allow for arbitrary code execution. For an attack to succeed, an adversary must convince a user to open a specially crafted Virtual Instrument (VI). This issue is particularly pertinent to users of NI LabVIEW versions up to and including 2025 Q1.

Affected Version(s)

LabVIEW Windows 0 <= 22.3.5

LabVIEW Windows 23.0.0 <= 23.3.6

LabVIEW Windows 24.0.0 <= 24.3.3

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl working with CISA
.
CVE-2025-2633 : Out of Bounds Read Vulnerability in NI LabVIEW Software