CVE-2025-64469: Stack-based Buffer Overflow in LVResource::DetachResource() in NI LabVIEW
There is a stack-based buffer overflow vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64469?
CVE-2025-64469 has a high severity due to its potential for information disclosure and arbitrary code execution.
How do I fix CVE-2025-64469?
To fix CVE-2025-64469, update to the latest version of NI LabVIEW beyond version 25.3.
What causes CVE-2025-64469 in NI LabVIEW?
CVE-2025-64469 is caused by a stack-based buffer overflow when parsing a corrupted VI file.
What are the potential impacts of CVE-2025-64469?
The impacts of CVE-2025-64469 include information disclosure and the possibility of arbitrary code execution.
What versions of NI LabVIEW are affected by CVE-2025-64469?
CVE-2025-64469 affects versions of NI LabVIEW up to but not including 25.3.