Description
A memory corruption vulnerability due to improper input validation in lvpict.cpp exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.
Problem types
CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input
Product status
Any version
23.0.0 (semver)
24.0.0 (semver)
25.0.0 (semver) before 25.3.0
Credits
Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative
References
www.ni.com/...-corruption-vulnerabilities-in-ni-labview.html