NI LabVIEW DLL Hijacking Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A DLL hijacking vulnerability has been identified in NI LabVIEW versions 2025 Q1 and prior. This vulnerability arises from an uncontrolled search path, which can be exploited by an attacker to execute arbitrary code. Successful exploitation requires the attacker to place a malicious DLL into the uncontrolled search path.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution.

Remediation

Users are advised to upgrade to LabVIEW 2025 Q1 Patch 2 or later. For deployed LabVIEW applications, the LabVIEW Run-Time Engine should also be patched.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
10.0
exploitability
2.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.