Executive brief
NI-PAL is a core software component used by many National Instruments hardware drivers to communicate between the operating system and laboratory equipment. A vulnerability in this component allows a user who already has basic access to a computer to read or modify sensitive system memory. This could allow an attacker to bypass security restrictions and gain full administrative control over the affected Windows or Linux system.
Technical details
A vulnerability exists in NI-PAL (NI Platform Abstraction Layer) due to improper validation of specified indices, positions, or offsets in input (CWE-1285). The flaw is located within the kernel-mode driver components (such as nipalk.sys on Windows). A local authenticated attacker with low privileges can exploit this by providing specially crafted input to the driver, enabling arbitrary read and write access to system memory. This capability can be leveraged to escalate privileges to SYSTEM (Windows) or root (Linux). The vulnerability affects versions 26.3.0 and prior on Windows, Linux Desktop, and NI Linux Real-Time. Patches are available in the 2026 Q2 release cycle.
Affected products
- National Instruments (NI) NI-PAL 26.3.0 and prior
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory
- 2026-06-02: patched: Fixed in NI-PAL 26.3.1 / 2026 Q2 releases