Executive brief
NI LabVIEW, a popular system-design platform and development environment for engineers and scientists, is vulnerable to a memory corruption flaw. An attacker could exploit this by tricking a user into opening a specially crafted LabVIEW Virtual Instrument (VI) file. Successful exploitation could allow an attacker to steal sensitive information or take full control of the affected computer.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in NI LabVIEW within the mgcore_SH_25_3!aligned_free() function. The flaw is triggered when the application processes a specially crafted Virtual Instrument (.vi) file. While the primary vulnerability is an out-of-bounds read, the vendor indicates it can lead to memory corruption, potentially resulting in arbitrary code execution or information disclosure. The attack requires local user interaction to open the malicious file. NI has released patches for various versions, including LabVIEW 2026 Q1 Patch 1, 2025 Q3 Patch 4, 2024 Q3 Patch 6, and 2023 Q3 Patch 9.
Affected products
- NI LabVIEW 2026 Q1 (26.1.0) and prior versions
Timeline
- 2026-04-07: disclosed
- 2026-04-07: advisory
- 2026-04-07: patched