Buffer Overflow Vulnerability in NI LabVIEW Software
CVE-2025-64469
8.5HIGH
What is CVE-2025-64469?
NI LabVIEW contains a stack-based buffer overflow vulnerability in the LVResFile::FindRsrcListEntry() function when it attempts to parse a malformed VI file. Exploiting this vulnerability allows an attacker to potentially leak sensitive information or execute arbitrary code on the affected system. To successfully exploit this vulnerability, an attacker must convince a user to open a specially crafted VI file, which could have dangerous repercussions for the integrity and confidentiality of the user's data. Users are advised to remain vigilant and ensure they are running the latest software updates.
Affected Version(s)
LabVIEW 0 <= 22.3.6
LabVIEW 23.1.0 <= 23.3.7
LabVIEW 24.1.0 <= 24.3.4
