CVE-2025-64466: Out-of-Bounds Read in lvre!ExecPostedProcRecPost() in NI LabVIEW
There is an out of bounds read vulnerability in NI LabVIEW in lvre!ExecPostedProcRecPost() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64466?
CVE-2025-64466 is classified as a critical severity vulnerability due to its potential for information disclosure and arbitrary code execution.
How do I fix CVE-2025-64466?
To mitigate CVE-2025-64466, update to the latest version of NI LabVIEW that addresses this vulnerability.
What impact does CVE-2025-64466 have on NI LabVIEW?
CVE-2025-64466 can lead to information disclosure or allow an attacker to execute arbitrary code on the affected system.
Is CVE-2025-64466 exploitable remotely?
CVE-2025-64466 requires local user interaction to exploit, specifically by opening a corrupted VI file.
Which versions of NI LabVIEW are affected by CVE-2025-64466?
CVE-2025-64466 affects NI LabVIEW versions up to but not including 25.3.