CVE-2026-64200
nicheOut-of-bounds read in NI DASYLab when opening crafted .DSB files
DASYLab, NI's data-acquisition software, contains an out-of-bounds read (CWE-125) caused by improper validation of user-supplied data, which reads past the end of an allocated heap buffer during string conversion. An attacker triggers the flaw by convincing a user to open a specially crafted .DSB file, so exploitation requires local access and user interaction. Per the CVSS 4.0 score of 8.5, impacts are rated high for confidentiality, integrity, and availability, though out-of-bounds reads most commonly expose process memory or crash the application. All DASYLab versions before 2026.0.0 are affected, meaning any deployment not yet on the 2026.0.0 release is exposed to malicious files from untrusted sources. There is currently no known exploitation: the flaw is not in CISA's KEV, has no public proof-of-concept, and EPSS assigns just a 0.1% probability of exploitation in the next 30 days.
What to do: Upgrade to DASYLab 2026.0.0 or later, which resolves this issue. Until patched, do not open .DSB files received from untrusted or unverified sources, and check asset inventories for any DASYLab installations that may handle third-party or customer-supplied data files.
| NI (National Instruments) DASYLab | All versions prior to 2026.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker to get a user to open a specially crafted .DSB file. This issue affects all versions before 2026.0.0.
- Weakness
- CWE-125
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.