Out-of-Bounds Read in NI LabVIEW Image Loading Enables Code Execution via Crafted VI
AI analysis
NI LabVIEW contains an integer conversion flaw (CWE-195) that causes an out-of-bounds read while loading images embedded in VI files. An attacker must persuade a user to open a specially crafted VI file, so exploitation depends on social engineering rather than a network-reachable service. If successful, the attacker can read memory for information disclosure or potentially achieve arbitrary code execution in the context of the LabVIEW user. Anyone running NI LabVIEW 2026 Q3 or any earlier version is affected, which spans a large share of the product's long-lived installed base. The issue was disclosed through ZDI (ZDI-26-631), but no public proof-of-concept is known, it is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.1%.
What to do: Upgrade LabVIEW to a release newer than 2026 Q3 once NI's patched build (see ZDI-26-631 and NI's advisory) is available in your maintenance channel. Until then, instruct staff not to open VI files from untrusted or unexpected sources, and inventory engineering workstations and test systems running LabVIEW 2026 Q3 or older to plan the update.
Affected
| ni labview | NI LabVIEW 2026 Q3 and all prior versions |
Estimated exposure
largeon the order of 100,000+ installed seats (NI's long-established engineering/test user base) — LabVIEW is widely deployed on engineering and test-bench workstations across manufacturing, R&D and academic labs (commonly cited in the hundreds of thousands of users), and the '2026 Q3 and prior' range covers essentially the entire…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
There is an integer conversion vulnerability resulting in an out-of-bounds read when loading images recently discovered in NI LabVIEW. This may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q3 and prior versions.