CVE-2025-64462: Out-of-Bounds Read in LVResFile::RGetMemFileHandle() in NI LabVIEW
There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::RGetMemFileHandle() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64462?
The severity of CVE-2025-64462 is high due to its potential for information disclosure and arbitrary code execution.
How do I fix CVE-2025-64462?
To fix CVE-2025-64462, update NI LabVIEW to the latest version that addresses this vulnerability.
What could an attacker achieve by exploiting CVE-2025-64462?
An attacker could achieve information disclosure or execute arbitrary code on the affected system by exploiting CVE-2025-64462.
What software is affected by CVE-2025-64462?
NI LabVIEW versions prior to 25.3 are affected by CVE-2025-64462.
What causes CVE-2025-64462?
CVE-2025-64462 is caused by an out of bounds read vulnerability in the LVResFile::RGetMemFileHandle() function when parsing a corrupted VI file.