NI LabVIEW
cpe:2.3:a:ni:labview:*:*:*:*:*:*:*
- 2025 Q1
- 2025
A memory corruption vulnerability has been identified in NI LabVIEW versions through 2025 Q1. This vulnerability arises from improper error handling when a VILinkObj is null, potentially allowing arbitrary code execution. Successful exploitation requires an attacker to persuade a user to open a specially crafted VI.
Exploitation of this vulnerability could lead to memory corruption, allowing for arbitrary code execution within the LabVIEW environment.
Users are advised to upgrade to LabVIEW 2025 Q3 or later. For LabVIEW 2025 Q1, a patch is in progress. Instructions for downloading the updated version are available on the NI Software Downloads page.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.