
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64468 is a use-after-free vulnerability in the sentry!sentry_span_set_data() function of NI LabVIEW, triggered when parsing a corrupted VI (Virtual Instrument) file. It affects NI LabVIEW 2025 Q3 (25.3) and all prior versions, spanning releases from 2022 Q1 through 2025 Q3 patch 2. The vulnerability was disclosed on December 18, 2025, by National Instruments (NI) as the CNA. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 8.5 (High) (NI Advisory, Red Hat CVE).
The vulnerability is classified as CWE-416 (Use After Free), occurring in the sentry!sentry_span_set_data() function during the parsing of a specially crafted or corrupted VI file. When LabVIEW processes such a malformed file, memory that has already been freed is subsequently accessed, creating conditions for memory corruption. The attack vector is local, requiring no privileges, but does require user interaction — specifically, a user must be socially engineered into opening a malicious .vi file. No public proof-of-concept code has been identified at this time (NI Advisory, Red Hat CVE).
Successful exploitation can result in information disclosure or arbitrary code execution with the privileges of the user running LabVIEW. Given that LabVIEW is widely used in industrial control, test and measurement, and scientific research environments, a compromised workstation could expose sensitive operational data or provide an attacker with a foothold for lateral movement within engineering or OT networks. The full triad of confidentiality, integrity, and availability is rated HIGH in both CVSS v3.1 and v4.0 assessments (NI Advisory, CISA ICS Advisory).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure (Red Hat CVE). The EPSS score is approximately 0.015% (0.000150), indicating a very low current probability of exploitation in the wild. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. CISA has, however, published an ICS advisory (ICSA-25-352-03) covering this and related LabVIEW memory corruption vulnerabilities (CISA ICS Advisory).
.vi) file designed to trigger the use-after-free condition in sentry!sentry_span_set_data() during file parsing.sentry_span_set_data() to access previously freed memory, resulting in memory corruption..vi files received via email or file shares, particularly from external or unknown sources; presence of VI files with anomalous file sizes or corrupted internal structures.LabVIEW.exe) spawning unexpected child processes (e.g., cmd.exe, powershell.exe, network utilities) following the opening of a VI file; application crashes or abnormal termination of LabVIEW shortly after opening a specific file.LabVIEW.exe or associated DLLs; crash dump files (.dmp) generated in the LabVIEW installation or user temp directory.NI has released patches addressing this vulnerability; users should update to a fixed version beyond LabVIEW 2025 Q3 (25.3) — specifically, versions released after the patch date of December 2025 (NI Advisory). As an interim workaround, users should avoid opening VI files from untrusted or unverified sources, and organizations should implement strict file validation and scanning procedures for VI files entering the environment. CISA also recommends minimizing network exposure for LabVIEW workstations and applying defense-in-depth principles for ICS/OT environments (CISA ICS Advisory).
CISA published ICS Advisory ICSA-25-352-03 covering this and related NI LabVIEW memory corruption vulnerabilities, signaling its relevance to industrial control system operators (CISA ICS Advisory). Security aggregator Infinit Security published a brief technical summary of the vulnerability (Infinit Security). Overall community reaction has been measured, consistent with the absence of public exploit code and active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."