CVE-2025-64467 Details
Description
There is an out of bounds read vulnerability in NI LabVIEW in LVResFile::FindRsrcListEntry() when parsing a corrupted VI file. This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q3 (25.3) and prior versions.
An out-of-bounds read vulnerability has been identified in NI LabVIEW versions 2025 Q3 (25.3) and prior. The issue arises in the LVResFile::FindRsrcListEntry() function when the software parses a corrupted VI file. This vulnerability could lead to information disclosure or arbitrary code execution. Exploitation requires an attacker to persuade a user to open a specially crafted VI file.
Users are advised to upgrade to NI LabVIEW 2025 Q3 Patch 3 or later. Instructions for downloading the update are available on the NI Software Downloads page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/multiple-memory-corruption-vulnerabilities-in-ni-labview.html | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ni labview | 2022 q1 2022 q3 2022 q3_patch1 2022 q3_patch2 2022 q3_patch4 2022 q3_patch5 2022 q3_patch6 2023 q1 2023 q3 2023 q3_patch1 2023 q3_patch2 2023 q3_patch3 2023 q3_patch4 2023 q3_patch5 2023 q3_patch6 2023 q3_patch7 2024 - 2024 q1 2024 q1_patch1 2024 q3 2024 q3_patch1 2024 q3_patch2 2024 q3_patch3 2024 q3_patch4 2025 q1 2025 q1_patch1 2025 q1_patch2 2025 q1_patch3 2025 q3 2025 q3_patch1 2025 q3_patch2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 24, 2025 | Initial Analysis | [email protected] |
| Dec 18, 2025 | New CVE Received | [email protected] |