Impact
An integer overflow flaw in NI LabVIEW allows an out‑of‑bounds write when processing a specially crafted VI file. Because the memory write can corrupt adjacent memory, the vulnerability may lead to information disclosure or arbitrary code execution, as indicated by CWE‑190.
Affected Systems
NI LabVIEW 2026 Q3 and all earlier releases are affected by this integer‑overflow defect, as specified by the vendor and documented in the advisory. Affected users must identify the LabVIEW edition and build they are running and apply the corresponding update.
Risk and Exploitability
With a CVSS score of 6.9, the flaw presents a moderate impact. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting that it has not yet been commonly exploited in the wild. Based on the description, it is inferred that the attacker must persuade a user to open a malicious VI file, indicating a local or social‑engineering attack vector rather than a remote network exploitation.
OpenCVE Enrichment