Home
HIGH: 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NHIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 22.3.4
affected
23.1.0 (semver) before 23.3.5
affected
24.1.0 (semver) before 24.3.2
affected
25.1.0 (semver) before 25.1.1
affected
Description
Out of bounds write vulnerability due to improper bounds checking in NI LabVIEW reading CPU info from cache that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.
Problem types
Product status
Any version before 22.3.4
23.1.0 (semver) before 23.3.5
24.1.0 (semver) before 24.3.2
25.1.0 (semver) before 25.1.1
Credits
Michael Heinzl working with CISA
References
www.ni.com/...ounds-write-vulnerabilities-in-ni-labview.html