Impact
An out-of-bounds read vulnerability in NI LabVIEW allows an attacker to read memory beyond the intended buffer, which can lead to information disclosure or arbitrary code execution when a user opens a specially crafted VI file. This weakness, identified as CWE-125 and CWE-787, compromises confidentiality and integrity of the system.
Affected Systems
NI LabVIEW version 2026 Q3 (26.3.0) and earlier releases.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity, and the exploit requires a user to open a malicious VI, suggesting a social‑engineering vector. The EPSS score is 0.00128 (less than 1%), indicating a very low probability of exploitation; the vulnerability is not listed in CISA's KEV catalog. Despite the low EPSS, the high severity and user‑action prerequisite still pose a notable risk to exposed installations.
OpenCVE Enrichment