CVE-2025-64464: Out-of-Bounds Read in lvre!VisaWriteFromFile() in NI LabVIEW
There is an out of bounds read vulnerability in NI LabVIEW in lvre!VisaWriteFromFile() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64464?
CVE-2025-64464 is considered critical due to the potential for information disclosure and arbitrary code execution.
How do I fix CVE-2025-64464?
To fix CVE-2025-64464, update NI LabVIEW to a version that is 25.3 or later.
What software is affected by CVE-2025-64464?
CVE-2025-64464 affects NI LabVIEW versions up to but not including 25.3.
What can happen if CVE-2025-64464 is exploited?
Exploitation of CVE-2025-64464 may lead to unauthorized information disclosure or execution of arbitrary code.
How likely is it that an attacker can exploit CVE-2025-64464?
Successful exploitation of CVE-2025-64464 requires a user to open a specially crafted corrupted VI file, making it reliant on user action.