CVE-2025-64462
LabVIEW vulnerability analysis and mitigation

Overview

CVE-2025-64462 is an out-of-bounds read vulnerability in NI LabVIEW within the LVResFile::RGetMemFileHandle() function, triggered when parsing a corrupted or specially crafted VI (Virtual Instrument) file. It affects NI LabVIEW 2025 Q3 (25.3) and all prior versions, spanning releases from 2022 Q1 through 2025 Q3 patch 2. The vulnerability was disclosed on December 18, 2025, with NVD initial analysis completed December 24, 2025. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High), as assigned by National Instruments (NI Advisory, Red Hat CVE).

Technical details

The root cause is an out-of-bounds read (CWE-125) in the LVResFile::RGetMemFileHandle() function of NI LabVIEW, which fails to properly validate memory boundaries when parsing VI resource files. An attacker can craft a malformed or corrupted .vi file that, when opened by a victim, causes the application to read memory beyond the allocated buffer. Exploitation requires local access and user interaction — specifically, a user must be socially engineered into opening the malicious VI file. No authentication or elevated privileges are required on the part of the attacker (NI Advisory, Infinit Sec).

Impact

Successful exploitation can result in information disclosure of sensitive memory contents or arbitrary code execution in the context of the user running LabVIEW, compromising confidentiality, integrity, and availability of the affected system. In industrial and research environments where LabVIEW is commonly deployed for test, measurement, and control applications, exploitation could expose proprietary data or allow an attacker to gain a foothold on engineering workstations. Lateral movement within operational technology (OT) or laboratory networks is a realistic downstream risk (NI Advisory, CISA ICS Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of active in-the-wild exploitation at this time (Red Hat CVE). The EPSS score is approximately 0.015% (0.000150), indicating a very low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA did publish an ICS advisory (ICSA-25-352-03) covering this and related LabVIEW memory corruption issues (CISA ICS Advisory). No threat actor attribution has been reported.

Exploitation steps

  1. Craft a malicious VI file: Create a specially crafted LabVIEW Virtual Instrument (.vi) file with a corrupted resource section that triggers an out-of-bounds read in LVResFile::RGetMemFileHandle() during parsing.
  2. Deliver the file to the target: Use social engineering techniques (e.g., phishing email, malicious download link, shared network drive) to deliver the crafted .vi file to a user running a vulnerable version of NI LabVIEW (2025 Q3 or earlier).
  3. Induce the user to open the file: Convince the target user to open the malicious VI file in LabVIEW, which triggers the vulnerable parsing code path.
  4. Trigger out-of-bounds read: The LVResFile::RGetMemFileHandle() function reads beyond the allocated memory buffer, potentially leaking sensitive memory contents or corrupting memory in a way that enables code execution.
  5. Achieve objective: Depending on memory layout and exploitation precision, the attacker may obtain sensitive information from process memory or achieve arbitrary code execution under the privileges of the LabVIEW user account (NI Advisory, Infinit Sec).

Indicators of compromise

  • File System: Unexpected or unknown .vi files received via email, downloaded from external sources, or placed on shared drives; VI files with anomalous file sizes or corrupted headers.
  • Process: LabVIEW process (LabVIEW.exe) crashing or generating access violation errors when opening specific VI files; unexpected child processes spawned by LabVIEW.
  • Logs: Application crash logs or Windows Event Logs showing faulting module related to LabVIEW resource file parsing; Dr. Watson or Windows Error Reporting entries referencing LVResFile or memory access violations.
  • Network: Outbound connections from the LabVIEW process to unexpected external IP addresses following the opening of a VI file (potential indicator of code execution payload).

Mitigation and workarounds

NI has released patches addressing this vulnerability; users should upgrade to a LabVIEW version beyond 2025 Q3 (25.3) as detailed in the vendor advisory (NI Advisory). As interim mitigations, organizations should train users not to open VI files from untrusted or unknown sources, implement strict file validation before opening VI files, and use application whitelisting to control file execution. Network segmentation of LabVIEW engineering workstations from broader corporate or OT networks is also recommended to limit potential blast radius (CISA ICS Advisory).

Community reactions

CISA published ICS Advisory ICSA-25-352-03 in December 2025 covering multiple memory corruption vulnerabilities in NI LabVIEW, including CVE-2025-64462, highlighting the relevance to industrial control system environments (CISA ICS Advisory). Security news outlets including IT Security News covered the disclosure, and the vulnerability was noted in CVE aggregation feeds and Bluesky security community posts shortly after publication. Community sentiment reflects moderate concern given LabVIEW's widespread use in industrial, scientific, and engineering settings, though the lack of public PoC and low EPSS score temper urgency.

Additional resources


SourceThis report was generated using AI

Related LabVIEW vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-32864HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32863HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32862HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32861HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026
CVE-2026-32860HIGH8.5
  • LabVIEW logoLabVIEW
  • cpe:2.3:a:ni:labview
NoYesApr 07, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management