Executive brief
NI LabVIEW, a popular system-design platform and development environment for engineers, is vulnerable to a memory corruption issue when processing specific project files. An attacker could trick a user into opening a malicious .lvclass file, potentially leading to unauthorized data access or the ability to run harmful code on the user's computer. This could compromise sensitive engineering data or disrupt critical operations.
Technical details
A memory corruption vulnerability (CWE-787: Out-of-bounds Write) exists in NI LabVIEW's file parsing logic for LV Class (.lvclass) files. The flaw is triggered when the application attempts to load a specially crafted, corrupted file, leading to an out-of-bounds write. While the attack vector is local, it requires user interaction to open the malicious file. Successful exploitation can result in arbitrary code execution or information disclosure within the context of the LabVIEW process. NI has released patches for LabVIEW versions 2023 through 2026 to address this issue.
Affected products
- NI LabVIEW 2026 Q1 (26.1.0) and prior versions
Timeline
- 2026-04-07: disclosed
- 2026-04-07: advisory: Vendor advisory published by NI
- 2026-04-07: patched: Patches released for LabVIEW 2023, 2024, 2025, and 2026 versions