PatchSiren cyber security CVE debrief
CVE-2025-64468 National Instruments CVE debrief
National Instruments LabVIEW contains a use-after-free vulnerability that triggers when opening a corrupted VI (Virtual Instrument) file. An attacker can exploit this by convincing a user to open a specially crafted VI file, potentially leading to arbitrary code execution. The vulnerability requires local access and user interaction, with a CVSS 3.1 score of 7.8 (HIGH). CISA published advisory ICSA-25-352-03 on December 18, 2025, coordinating disclosure with National Instruments.
- Vendor
- National Instruments
- Product
- LabVIEW
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-12-18
- Original CVE updated
- 2025-12-18
- Advisory published
- 2025-12-18
- Advisory updated
- 2025-12-18
Who should care
Organizations using National Instruments LabVIEW in engineering, test, measurement, and industrial automation environments. Particularly critical for environments where VI files may be shared between users or obtained from external sources. Not applicable to KEV at time of publication.
Technical summary
A use-after-free condition exists in LabVIEW's VI file parsing logic. When processing a malformed or corrupted VI file, memory is freed and subsequently accessed, creating conditions for arbitrary code execution. The vulnerability is triggered through user interaction (opening a malicious file) and executes with the privileges of the LabVIEW process.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade affected LabVIEW installations to patched versions: LabVIEW 2025 Q3 Patch 3 or later, LabVIEW 2024 Q3 Patch 5 or later, LabVIEW 2023 Q3 Patch 8 or later, or LabVIEW 2022 Q3 Patch 7 or later. LabVIEW 2021 is notin
- Implement application whitelisting to prevent execution of untrusted VI files.
- Train users to avoid opening VI files from untrusted sources and to verify file origins before opening.
- Apply defense-in-depth strategies for industrial control systems environments per CISA guidance.
Evidence notes
Source: CISA CSAF advisory ICSA-25-352-03. CVSS 3.1 vector: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. Attack vector requires local access with user interaction (opening a malicious VI file).
Sources and references
Verified primary and authoritative sources
-
CVE-2025-64468 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-64468
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-64468 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-64468
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-352-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-352-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.