ZeroHour

CVE-2026-64198

niche

Out-of-bounds read in NI DASYLab when opening crafted .DSB files

CVSS 4.0
8.5 high
EPSS
<1%p2
Published
()
Modified
AI analysis

NI DASYLab contains an out-of-bounds read vulnerability (CWE-125) caused by improper validation of user-supplied data during file handling, which causes the application to read a few bytes past the end of an allocated heap buffer. Exploitation requires a user to open a specially crafted .DSB file, making this a user-interaction-dependent, local-vector issue rather than a remotely exploitable flaw (consistent with the CVSS 4.0 local attack vector and required user interaction). A successful attack primarily exposes a small amount of adjacent heap memory; the vendor-assigned CVSS 4.0 base score of 8.5 (high) rates the potential impact to confidentiality, integrity, and availability as high, though no public proof-of-concept or observed exploitation is documented. All DASYLab versions prior to 2026.0.0 are affected. There are no signs of active exploitation: the flaw is not in CISA KEV, no public PoC is known, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.

What to do: Upgrade DASYLab to version 2026.0.0 or later, which resolves this issue. Until patched, instruct users not to open .DSB files from untrusted or unknown sources, since exploitation depends entirely on opening a maliciously crafted file. Inventory Windows workstations running DASYLab (e.g., via software inventory tools) to identify installations on versions below 2026.0.0.

Affected
NI (National Instruments) DASYLaball versions before 2026.0.0
Estimated exposure
nichelikely in the low tens of thousands of licensed desktop installations worldwide at most (estimate) — No install-base figures or internet-exposure scans were provided; DASYLab is a niche, per-seat desktop data-acquisition application typically run on individual lab or test-bench workstations rather than exposed servers, so the affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.

Weakness
CWE-125
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.