8.5

CVE-2026-32864

Out-of-Bounds Read in mgcore_SH_25_3!aligned_free()

There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI file. This vulnerability affects NI LabVIEW 2026 Q1 (26.1.0) and prior versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ni ≫ Labview Version <= 2022
Ni ≫ Labview Version 2023 Update q1
Ni ≫ Labview Version 2023 Update q3
Ni ≫ Labview Version 2023 Update q3_patch1
Ni ≫ Labview Version 2023 Update q3_patch2
Ni ≫ Labview Version 2023 Update q3_patch3
Ni ≫ Labview Version 2023 Update q3_patch4
Ni ≫ Labview Version 2023 Update q3_patch5
Ni ≫ Labview Version 2023 Update q3_patch6
Ni ≫ Labview Version 2023 Update q3_patch7
Ni ≫ Labview Version 2023 Update q3_patch8
Ni ≫ Labview Version 2024 Update -
Ni ≫ Labview Version 2024 Update q1
Ni ≫ Labview Version 2024 Update q1_patch1
Ni ≫ Labview Version 2024 Update q3
Ni ≫ Labview Version 2024 Update q3_patch1
Ni ≫ Labview Version 2024 Update q3_patch2
Ni ≫ Labview Version 2024 Update q3_patch3
Ni ≫ Labview Version 2024 Update q3_patch4
Ni ≫ Labview Version 2024 Update q3_patch5
Ni ≫ Labview Version 2025 Update q1
Ni ≫ Labview Version 2025 Update q1_patch1
Ni ≫ Labview Version 2025 Update q1_patch2
Ni ≫ Labview Version 2025 Update q1_patch3
Ni ≫ Labview Version 2025 Update q3
Ni ≫ Labview Version 2025 Update q3_patch1
Ni ≫ Labview Version 2025 Update q3_patch2
Ni ≫ Labview Version 2025 Update q3_patch3
Ni ≫ Labview Version 2026 Update q1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.14% 0.037
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@ni.com 8.5 0 0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
security@ni.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/2026/memory-corruption-vulnerabilities-in-ni-labview.html
Vendor Advisory