CVE-2025-64461
LabVIEW vulnerability analysis and mitigation

Overview

CVE-2025-64461 is an out-of-bounds write vulnerability in NI LabVIEW affecting the mgocre_SH_25_3!RevBL() function when parsing a corrupted VI (Virtual Instrument) file. Successful exploitation can result in information disclosure or arbitrary code execution, requiring a user to open a specially crafted VI file. The vulnerability affects NI LabVIEW 2025 Q3 (25.3) and all prior versions, spanning releases from at least 2022 Q1 through 2025 Q3 patch 2. It was published on December 18, 2025, with initial NVD analysis completed December 24, 2025. The CNA-assigned CVSS v3.1 score is 7.8 (High) and CVSS v4.0 score is 8.5 (High) (NI Advisory).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write), occurring in the mgocre_SH_25_3!RevBL() function within LabVIEW's VI file parsing logic. When LabVIEW processes a malformed or corrupted VI file, insufficient bounds checking allows an attacker-controlled write operation to occur outside the intended memory buffer. The attack vector is local with no privileges required, but user interaction is necessary — an attacker must socially engineer a target into opening a specially crafted .vi file. No public proof-of-concept code has been identified at this time (NI Advisory).

Impact

Successful exploitation can lead to arbitrary code execution or information disclosure on the affected system, with high impact to confidentiality, integrity, and availability. An attacker who tricks a LabVIEW user into opening a malicious VI file could gain code execution in the context of the user running LabVIEW, potentially enabling data theft, installation of malware, or further lateral movement within industrial or engineering environments where LabVIEW is commonly deployed. Given LabVIEW's prevalence in industrial control systems (ICS) and test/measurement environments, exploitation could have significant operational consequences (NI Advisory, CISA ICS Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-64461. The EPSS score is approximately 0.015% (0.000150), indicating a very low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires user interaction (opening a malicious VI file), which limits opportunistic exploitation but makes it suitable for targeted spear-phishing campaigns against engineering or ICS personnel (NI Advisory, CISA ICS Advisory).

Exploitation steps

  1. Reconnaissance: Identify targets who use NI LabVIEW in engineering, research, or industrial control environments — common in manufacturing, aerospace, and laboratory settings.
  2. Craft malicious VI file: Create a specially crafted LabVIEW VI (.vi) file that contains a corrupted or malformed structure designed to trigger the out-of-bounds write in mgocre_SH_25_3!RevBL() during file parsing.
  3. Deliver the payload: Distribute the malicious VI file via phishing email, a compromised file-sharing platform, or a poisoned project repository targeting LabVIEW users.
  4. Trigger exploitation: When the victim opens the crafted VI file in a vulnerable version of LabVIEW (2025 Q3 or prior), the parser processes the malformed data, causing an out-of-bounds write in memory.
  5. Achieve code execution or information disclosure: Depending on the crafted payload and memory layout, the attacker may achieve arbitrary code execution in the context of the LabVIEW process or leak sensitive memory contents (NI Advisory).

Indicators of compromise

  • File System: Unexpected or unsolicited .vi files received via email attachments, downloads, or shared drives; VI files with unusual file sizes or metadata inconsistencies.
  • Process: LabVIEW process (LabVIEW.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, curl, network utilities) shortly after opening a VI file; crashes or abnormal termination of LabVIEW.
  • Network: Outbound network connections from the LabVIEW process to unknown or suspicious external IP addresses following VI file opening; DNS queries to unfamiliar domains initiated by the LabVIEW process.
  • Logs: Application crash logs or Windows Event Log entries (Event ID 1000/1001) referencing LabVIEW.exe or associated DLLs around the time a VI file was opened; memory access violation errors in LabVIEW logs.

Mitigation and workarounds

NI has released patches addressing this and related memory corruption vulnerabilities in LabVIEW. Users should update to a patched version as detailed in the NI security advisory. As a workaround, organizations should avoid opening VI files from untrusted or unverified sources, and apply strict file-sharing controls in environments where LabVIEW is deployed. CISA has also issued an ICS advisory (ICSA-25-352-03) recommending users follow NI's guidance and apply defense-in-depth measures (NI Advisory, CISA ICS Advisory).

Community reactions

CISA issued ICS Advisory ICSA-25-352-03 in response to this and related NI LabVIEW memory corruption vulnerabilities, highlighting the relevance to industrial control system environments (CISA ICS Advisory). Security news outlets including IT Security News covered the disclosure, and the vulnerability was noted in CVE aggregation feeds. Community reaction has been limited, consistent with the low EPSS score and absence of public exploit code.

Additional resources


SourceThis report was generated using AI

Related LabVIEW vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-32864HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32863HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32862HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32861HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32860HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management