CVE-2026-64197
nicheOut-of-bounds write in NI DASYLab via crafted .DSB files
NI DASYLab contains an out-of-bounds write (CWE-787) caused by improper validation of user-supplied data, allowing a write past the end of an allocated data structure. An attacker must convince a user to open a specially crafted .DSB file, typically via email or a shared drive, to trigger the flaw. Successful exploitation could compromise the local system with high impact to confidentiality, integrity, and availability (CVSS 4.0 score 8.5), since the code runs with the user's privileges. All DASYLab versions prior to 2026.0.0 are affected, meaning virtually every deployed installation except the newest release is in scope. There is no evidence of exploitation so far: the flaw is not in CISA's KEV, EPSS assigns it only a 0.1% probability of exploitation in the next 30 days, and no public proof-of-concept is known.
What to do: Upgrade to DASYLab 2026.0.0 or later, which fixes this issue. Until patched, avoid opening .DSB files from untrusted or unknown sources and inventory workstations running DASYLab, prioritizing systems that routinely receive data files from external parties. Because exploitation requires user interaction, user awareness about opening unsolicited data-acquisition files is the primary interim mitigation.
| NI (National Instruments) DASYLab | All versions before 2026.0.0 (fixed in 2026.0.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
- Weakness
- CWE-787
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.