CVE-2025-64465: Out-of-Bounds Read in lvre!DataSizeTDR() in NI LabVIEW
There is an out of bounds read vulnerability in NI LabVIEW in lvre!DataSizeTDR() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64465?
CVE-2025-64465 has a high severity rating as it can lead to information disclosure or arbitrary code execution.
How do I fix CVE-2025-64465?
To fix CVE-2025-64465, ensure that you update NI LabVIEW to the latest fixed version beyond 25.3.
What versions of NI LabVIEW are affected by CVE-2025-64465?
CVE-2025-64465 affects NI LabVIEW versions up to but not including 25.3.
What type of vulnerability is CVE-2025-64465?
CVE-2025-64465 is an out of bounds read vulnerability found in the lvre!DataSizeTDR() function.
How can an attacker exploit CVE-2025-64465?
An attacker can exploit CVE-2025-64465 by tricking a user into opening a specially crafted VI file.