CVE-2025-64467: Out-of-Bounds Read in LVResFile::FindRsrcListEntry() in NI LabVIEW
There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64467?
CVE-2025-64467 is classified as a critical vulnerability due to its potential for information disclosure and arbitrary code execution.
How do I fix CVE-2025-64467?
To fix CVE-2025-64467, users should update to the latest version of NI LabVIEW that addresses this vulnerability.
What causes the CVE-2025-64467 vulnerability?
CVE-2025-64467 is caused by an out of bounds read in the LVResFile::FindRsrcListEntry() function when processing a corrupted VI file.
Who is affected by CVE-2025-64467?
CVE-2025-64467 affects users of National Instruments LabVIEW versions up to but not including 25.3.
What type of attack leverages CVE-2025-64467?
CVE-2025-64467 can be exploited when an attacker tricks a user into opening a specially crafted corrupt VI file.