ZeroHour

CVE-2026-64200

niche

Out-of-bounds read in NI DASYLab when opening crafted .DSB files

CVSS 4.0
8.5 high
EPSS
<1%p2
Published
()
Modified
AI analysis

DASYLab, NI's data-acquisition software, contains an out-of-bounds read (CWE-125) caused by improper validation of user-supplied data, which reads past the end of an allocated heap buffer during string conversion. An attacker triggers the flaw by convincing a user to open a specially crafted .DSB file, so exploitation requires local access and user interaction. Per the CVSS 4.0 score of 8.5, impacts are rated high for confidentiality, integrity, and availability, though out-of-bounds reads most commonly expose process memory or crash the application. All DASYLab versions before 2026.0.0 are affected, meaning any deployment not yet on the 2026.0.0 release is exposed to malicious files from untrusted sources. There is currently no known exploitation: the flaw is not in CISA's KEV, has no public proof-of-concept, and EPSS assigns just a 0.1% probability of exploitation in the next 30 days.

What to do: Upgrade to DASYLab 2026.0.0 or later, which resolves this issue. Until patched, do not open .DSB files received from untrusted or unverified sources, and check asset inventories for any DASYLab installations that may handle third-party or customer-supplied data files.

Affected
NI (National Instruments) DASYLabAll versions prior to 2026.0.0
Estimated exposure
nichelikely on the order of tens of thousands of engineering/lab workstation installations, not internet-exposed services — DASYLab is a specialized NI data-acquisition package typically installed on individual lab and test-bench workstations rather than exposed servers, and no public install counts are available, so the footprint is estimated as niche; exact…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.

Weakness
CWE-125
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.