NI LabVIEW DLL Hijacking Vulnerability in Error Reporting Component Allowing Arbitrary Code Execution

Vulnerability

A DLL hijacking vulnerability has been identified in NI LabVIEW versions 2025 Q1 and prior. This issue arises from an uncontrolled search path when the application loads NI Error Reporting, potentially leading to arbitrary code execution. Exploitation requires an attacker to place a malicious DLL into the vulnerable search path.

Impact

Exploitation of this vulnerability could allow for arbitrary code execution on the affected system.

Remediation

Users are advised to upgrade to LabVIEW 2025 Q1 Patch 2 or later. For LabVIEW 2024, 2023, and 2022, similar upgrade instructions apply. LabVIEW 2021 and prior versions are not in mainstream support.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
10.0
exploitability
2.9
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.