ZeroHour

CVE-2026-64196

niche

Out-of-bounds write in NI DASYLab via crafted .DSB files

CVSS 4.0
8.5 high
EPSS
<1%p2
Published
()
Modified
AI analysis

NI DASYLab contains an out-of-bounds write vulnerability (CWE-787) caused by improper validation of user-supplied data, allowing a write past the end of an allocated heap buffer when the application parses a DASYLab data file. An attacker exploits it by convincing a user to open a specially crafted .DSB file; because the CVSS 4.0 impact metrics rate confidentiality, integrity, and availability as high, successful exploitation could plausibly allow arbitrary code execution in the context of the DASYLab user. All DASYLab versions prior to 2026.0.0 are affected, meaning essentially any deployed copy of the product on lab or test workstations is vulnerable until patched. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a 0.1% probability of exploitation in the next 30 days, so no active exploitation is known.

What to do: Upgrade DASYLab to version 2026.0.0 or later, which is the first release with this flaw fixed. Until patched, do not open .DSB files from untrusted or unsolicited sources on workstations running DASYLab, and inventory lab and test-bench machines for DASYLab installs to prioritize remediation.

Affected
NI (National Instruments, part of Emerson) DASYLaball versions before 2026.0.0
Estimated exposure
nichelikely on the order of tens of thousands of installed workstations at most (specialized lab DAQ software) — DASYLab is a niche NI data-acquisition application installed on individual lab/test workstations rather than broadly deployed or internet-exposed, and no public install counts are available, so this is a low-confidence order-of-magnitude…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated heap. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.

Weakness
CWE-787
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.