Out of Bounds Read Vulnerability in NI LabVIEW
CVE-2025-2634

7.3HIGH

Key Information:

Vendor

Ni

Status
Vendor
CVE Published:
23 July 2025

What is CVE-2025-2634?

An out of bounds read vulnerability exists in NI LabVIEW due to improper bounds checking in the font manager. This flaw could potentially allow an attacker to exploit the system if a user opens a specially crafted virtual instrument (VI). Exploiting this vulnerability could lead to information disclosure or arbitrary code execution, compromising the integrity and security of the affected systems. Users of NI LabVIEW 2025 Q1 and earlier versions are encouraged to take immediate action to mitigate potential risks.

Affected Version(s)

LabVIEW Windows 0 <= 22.3.5

LabVIEW Windows 23.0.0 <= 23.3.6

LabVIEW Windows 24.0.0 <= 24.3.3

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl working with CISA
.
CVE-2025-2634 : Out of Bounds Read Vulnerability in NI LabVIEW