CVE-2026-64198
nicheOut-of-bounds read in NI DASYLab when opening crafted .DSB files
NI DASYLab contains an out-of-bounds read vulnerability (CWE-125) caused by improper validation of user-supplied data during file handling, which causes the application to read a few bytes past the end of an allocated heap buffer. Exploitation requires a user to open a specially crafted .DSB file, making this a user-interaction-dependent, local-vector issue rather than a remotely exploitable flaw (consistent with the CVSS 4.0 local attack vector and required user interaction). A successful attack primarily exposes a small amount of adjacent heap memory; the vendor-assigned CVSS 4.0 base score of 8.5 (high) rates the potential impact to confidentiality, integrity, and availability as high, though no public proof-of-concept or observed exploitation is documented. All DASYLab versions prior to 2026.0.0 are affected. There are no signs of active exploitation: the flaw is not in CISA KEV, no public PoC is known, and EPSS estimates only a 0.1% probability of exploitation in the next 30 days.
What to do: Upgrade DASYLab to version 2026.0.0 or later, which resolves this issue. Until patched, instruct users not to open .DSB files from untrusted or unknown sources, since exploitation depends entirely on opening a maliciously crafted file. Inventory Windows workstations running DASYLab (e.g., via software inventory tools) to identify installations on versions below 2026.0.0.
| NI (National Instruments) DASYLab | all versions before 2026.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
- Weakness
- CWE-125
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.