ZeroHour

CVE-2026-64197

niche

Out-of-bounds write in NI DASYLab via crafted .DSB files

CVSS 4.0
8.5 high
EPSS
<1%p2
Published
()
Modified
AI analysis

NI DASYLab contains an out-of-bounds write (CWE-787) caused by improper validation of user-supplied data, allowing a write past the end of an allocated data structure. An attacker must convince a user to open a specially crafted .DSB file, typically via email or a shared drive, to trigger the flaw. Successful exploitation could compromise the local system with high impact to confidentiality, integrity, and availability (CVSS 4.0 score 8.5), since the code runs with the user's privileges. All DASYLab versions prior to 2026.0.0 are affected, meaning virtually every deployed installation except the newest release is in scope. There is no evidence of exploitation so far: the flaw is not in CISA's KEV, EPSS assigns it only a 0.1% probability of exploitation in the next 30 days, and no public proof-of-concept is known.

What to do: Upgrade to DASYLab 2026.0.0 or later, which fixes this issue. Until patched, avoid opening .DSB files from untrusted or unknown sources and inventory workstations running DASYLab, prioritizing systems that routinely receive data files from external parties. Because exploitation requires user interaction, user awareness about opening unsolicited data-acquisition files is the primary interim mitigation.

Affected
NI (National Instruments) DASYLabAll versions before 2026.0.0 (fixed in 2026.0.0)
Estimated exposure
nichelikely on the order of tens of thousands of installed users (no public install counts; specialized desktop DAQ software) — DASYLab is a niche Windows data-acquisition and analysis application used mainly in lab and industrial test settings, so the exposed population is far smaller than mainstream desktop software; the figure is an order-of-magnitude estimate…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.

Weakness
CWE-787
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.