CVE-2025-64461: Out of Bounds Write in mgocre_SH_25_3!RevBL() in NI LabVIEW
There is an out of bounds write vulnerability in NI LabVIEW in mgocreSH253!RevBL() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64461?
CVE-2025-64461 is classified as a critical severity vulnerability.
How do I fix CVE-2025-64461?
To mitigate CVE-2025-64461, update to the latest version of NI LabVIEW available, specifically version 25.3 or later.
What are the potential risks associated with CVE-2025-64461?
The risks associated with CVE-2025-64461 include information disclosure and the possibility of arbitrary code execution.
Who is affected by CVE-2025-64461?
CVE-2025-64461 affects users of NI LabVIEW version up to but not including 25.3.
How can an attacker exploit CVE-2025-64461?
An attacker can exploit CVE-2025-64461 by convincing a user to open a specially crafted corrupted VI file.