National Instruments Circuit Design Suite versions 14.3.1 and earlier are affected by two critical memory corruption vulnerabilities, CVE-2025-6033 and CVE-2025-6034. The first vulnerability, CVE-2025-6033, is caused by an out-of-bounds write in the XML_Serialize() function when using the SymbolEditor component. This flaw can result in information disclosure or arbitrary code execution if a user opens a specially crafted .sym file. The second vulnerability, CVE-2025-6034, is due to an out-of-bounds read in the DefaultFontOptions() function, also within the SymbolEditor, and can similarly lead to information disclosure or arbitrary code execution under the same exploitation conditions. Both vulnerabilities require user interaction, specifically opening a malicious .sym file, and are not remotely exploitable without such action. CISA has issued an advisory highlighting that successful exploitation could allow attackers to corrupt memory, potentially leading to the execution of arbitrary code or the disclosure of sensitive information. The vulnerabilities are rated as high severity, with CVSS v4 scores of 8.4 and v3.1 base scores of 7.8, reflecting the significant risk posed to affected systems. The flaws impact sectors such as communications, defense industrial base, and government services, where Circuit Design Suite is commonly deployed. The vulnerabilities stem from improper handling of memory resources, specifically type confusion and out-of-bounds memory access. National Instruments has acknowledged the issues and coordinated disclosure with security researchers and CISA. No evidence suggests that these vulnerabilities are being actively exploited in the wild at this time. Users are advised to avoid opening untrusted .sym files and to apply any available patches or mitigations as soon as they are released. The vulnerabilities highlight the ongoing risks associated with complex file parsing in engineering and design software. Organizations using affected versions should review their security posture and consider additional controls to limit exposure. The advisories recommend monitoring for unusual activity and ensuring that only trusted files are opened within the application. National Instruments has provided contact information for further security guidance and is expected to release updates addressing these vulnerabilities. The disclosure underscores the importance of regular software updates and user awareness in mitigating targeted attacks via crafted files.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
On September 30, 2025, CISA announced the release of ten new ICS advisories, including the National Instruments Circuit Design Suite advisory. The release provided technical details and mitigation guidance for multiple industrial control system vendors.
CISA published advisory ICSA-25-273-06 detailing the two high-severity vulnerabilities in National Instruments Circuit Design Suite and noting there was no evidence of public exploitation. The advisory said affected deployments span multiple critical infrastructure sectors worldwide.
National Instruments released version 14.3.2 to fix CVE-2025-6033 and CVE-2025-6034 affecting Circuit Design Suite 14.3.1 and earlier. CISA advised users to update immediately and apply additional mitigations such as network isolation and secure remote access.
Michael Heinzl reported two vulnerabilities in National Instruments Circuit Design Suite to CISA: CVE-2025-6033, a type confusion issue in XML_Serialize(), and CVE-2025-6034, an out-of-bounds read in DefaultFontOptions(). Both issues could allow local memory corruption, potentially leading to information disclosure or arbitrary code execution.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.