Out of Bounds Read Vulnerability in NI LabVIEW Software
CVE-2025-2633
7.3HIGH
What is CVE-2025-2633?
An out of bounds read vulnerability has been identified in NI LabVIEW, specifically within the function lvre!UDecStrToNum. This vulnerability arises from inadequate bounds checking, which can lead to potential information disclosure or allow for arbitrary code execution. For an attack to succeed, an adversary must convince a user to open a specially crafted Virtual Instrument (VI). This issue is particularly pertinent to users of NI LabVIEW versions up to and including 2025 Q1.
Affected Version(s)
LabVIEW Windows 0 <= 22.3.5
LabVIEW Windows 23.0.0 <= 23.3.6
LabVIEW Windows 24.0.0 <= 24.3.3