Out of Bounds Read Vulnerability in NI LabVIEW by National Instruments
CVE-2025-64464

8.5HIGH

Key Information:

Vendor

Ni

Status
Vendor
CVE Published:
18 December 2025

What is CVE-2025-64464?

NI LabVIEW is susceptible to an out of bounds read vulnerability in the function lvre!VisaWriteFromFile(). This flaw occurs during the parsing of corrupted VI files, which could lead to unauthorized information disclosure or the execution of arbitrary code. Attackers would need to trick a user into opening a specially crafted VI file to exploit this vulnerability, potentially compromising system integrity and confidentiality.

Affected Version(s)

LabVIEW 0 <= 22.3.6

LabVIEW 23.1.0 <= 23.3.7

LabVIEW 24.1.0 <= 24.3.4

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl working with CISA
.
CVE-2025-64464 : Out of Bounds Read Vulnerability in NI LabVIEW by National Instruments