CVE-2025-7848
7.8NI · LabVIEW
A memory corruption vulnerability in NI LabVIEW due to improper input validation in lvpict.cpp allows for arbitrary code execution when a user opens a specially crafted VI file.
Executive summary
A critical memory corruption vulnerability in NI LabVIEW allows for arbitrary code execution, requiring urgent attention to mitigate the risk of system compromise.
Vulnerability
The vulnerability is a memory corruption flaw (CWE-1285) within the lvpict.cpp component. Exploitation requires no authentication but necessitates user interaction, as the attacker must trick a user into opening a malicious Virtual Instrument (VI) file.
Business impact
The ability to achieve arbitrary code execution poses a severe risk to organizational security, potentially allowing an attacker to gain full control over the affected workstation. Given the CVSS 4.0 score of 7.8, the impact is considered high, as it could lead to unauthorized data access, intellectual property theft, or the deployment of ransomware within the development environment.
Remediation
Immediate Action: Review the official NI security advisory and apply the necessary software updates to version 25.3.0 or later as soon as they become available.
Proactive Monitoring: Monitor endpoint activity for unusual process execution or unauthorized file modifications originating from the LabVIEW application.
Compensating Controls: Implement strict email and file transfer policies to prevent users from opening untrusted or unsolicited VI files from unknown sources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations should immediately identify all systems running the affected versions of NI LabVIEW. Until patches are applied, users must be cautioned against opening VI files received from unverified or suspicious origins. Prioritize the deployment of vendor-supplied security updates to eliminate the underlying vulnerability and prevent potential exploitation.
More NI CVEs
Sources
Originally found and disclosed by Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative, per the CVE Program record.