Description
There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
Problem types
CWE-121 - Stack-based Buffer Overflow
Product status
Any version
23.1.0 (semver)
24.1.0 (semver)
25.1.0 (semver)
Credits
Michael Heinzl working with CISA
References
www.ni.com/...-corruption-vulnerabilities-in-ni-labview.html
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.