ZeroHour

CVE-2026-64195

niche

Out-of-Bounds Write in NI DASYLab When Opening Crafted .DSB Files

CVSS 4.0
8.5 high
EPSS
<1%p2
Published
()
Modified
AI analysis

DASYLab, NI's (National Instruments/Emerson) data acquisition software, contains an out-of-bounds write flaw caused by insufficient validation of user-supplied data when parsing files. An attacker triggers the issue by convincing a user to open a specially crafted .DSB file, and the memory corruption could allow arbitrary code execution with the privileges of that user. All DASYLab versions prior to 2026.0.0 are affected. Users running older releases, typically engineers on workstations that import measurement files from external sources, are exposed to this social-engineering-driven attack. As of now there is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.1% chance of exploitation in the next 30 days.

What to do: Upgrade DASYLab to version 2026.0.0 or later, which fixes this issue. Until patched, do not open .DSB files from untrusted or unknown sources, and check whether any engineering or lab workstations in your environment run DASYLab versions prior to 2026.0.0.

Affected
NI (National Instruments) DASYLaball versions before 2026.0.0
Estimated exposure
nichelikely on the order of low tens of thousands of installations worldwide (specialized DAQ software; no public install counts) — DASYLab is a niche test-and-measurement DAQ package used mainly by individual engineering workstations and lab benches, and NI does not publish active-install counts, so the estimate rests on the product's specialized deployment pattern…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

There is an out-of-bounds write vulnerability in DASYLab due to lack of proper validation of user-supplied data. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.

Weakness
CWE-787
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.