CVE-2025-7849

7.8

NI · LabVIEW

A memory corruption vulnerability in NI LabVIEW allows for arbitrary code execution when a user opens a specially crafted VI file.

Executive summary

A critical memory corruption vulnerability in NI LabVIEW could allow an attacker to achieve arbitrary code execution by tricking a user into opening a malicious VI file.

Vulnerability

This vulnerability is caused by improper error handling when a VILinkObj is null, leading to memory corruption. Exploitation requires user interaction, specifically convincing a victim to open a specially crafted VI file within the application.

Business impact

The potential for arbitrary code execution poses a severe risk to organizational security, as it allows attackers to run malicious commands with the privileges of the logged-in user. While the CVSS score of 7.8 reflects a High severity, the ability to execute code could lead to full system compromise, data theft, or lateral movement within the network. Organizations relying on LabVIEW for critical industrial or research workflows face significant operational risk if these systems are compromised.

Remediation

Immediate Action: Update all installations of NI LabVIEW to the latest patched version provided by the vendor, which addresses the memory corruption flaw.

Proactive Monitoring: Monitor endpoint activity for unusual process execution patterns or unexpected file system modifications initiated by the LabVIEW process.

Compensating Controls: Implement strict application allowlisting and user awareness training to discourage opening untrusted or unsolicited VI files from external sources.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for total system impact through arbitrary code execution, this vulnerability should be prioritized for patching. IT administrators must ensure that all LabVIEW environments are updated to version 25.3.0 or later to neutralize the risk. Until patches are applied, users should exercise extreme caution when handling VI files from unknown or untrusted origins.

More NI CVEs

Sources

Originally found and disclosed by Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative, per the CVE Program record.