CVE-2025-64463: Out-of-Bounds Read in LVResource::DetachResource() in NI LabVIEW
There is an out of bounds read vulnerability in NI LabVIEW in LVResource::DetachResource() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64463?
CVE-2025-64463 has a high severity rating due to the potential for information disclosure and arbitrary code execution.
How do I fix CVE-2025-64463?
To fix CVE-2025-64463, update your National Instruments LabVIEW software to a version later than 25.3.
What impacts can I expect from CVE-2025-64463?
CVE-2025-64463 can lead to exposure of sensitive information and may allow attackers to execute arbitrary code.
Who is affected by CVE-2025-64463?
CVE-2025-64463 affects users of National Instruments LabVIEW prior to version 25.3.
What causes CVE-2025-64463?
CVE-2025-64463 is caused by an out of bounds read vulnerability in the LVResource::DetachResource() function when handling corrupted VI files.