Executive brief
NI LabVIEW is a graphical programming environment used by engineers and scientists to develop test, measurement, and automation applications. An integer overflow vulnerability can allow attackers to write data outside a buffer's intended boundaries, potentially leading to unauthorized information access or execution of malicious code when a user opens a specially crafted VI project file. This could compromise systems used for critical testing and control applications.
Technical details
The vulnerability is an integer overflow (CWE-190) in NI LabVIEW that results in an out-of-bounds write condition. The attack requires a specially crafted VI file and user interaction (the user must open the file), making it a local attack vector with no privilege requirement. Successful exploitation can result in information disclosure (C:L) and arbitrary code execution (I:L via CVSS 3.1, or I:H via CVSS 4.0), giving attackers the ability to execute code in the context of the LabVIEW process. Patches are available through NI Package Manager, Software Downloads, or NI Update Service for affected versions (2026 Q3 and prior; specific patched versions provided for 2023–2026).
Affected products
- NI LabVIEW 2026 Q3 and prior
Timeline
- 2026-08-25: disclosed
- 2026-09-01: patched: Patches available for LabVIEW 2023 Q3 Patch 10, 2024 Q3 Patch 7, 2025 Q3 Patch 5, and 2026 Q3 Patch 1 or later