7.8

CVE-2025-2629

DLL Hijacking Vulnerability in NI LabVIEW When Loading NI Error Reporting

There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting.  This vulnerability may result in arbitrary code execution.  Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path.  This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ni ≫ Labview Version <= 2021
Ni ≫ Labview Version 2022 Update q1
Ni ≫ Labview Version 2022 Update q3
Ni ≫ Labview Version 2022 Update q3_patch1
Ni ≫ Labview Version 2022 Update q3_patch2
Ni ≫ Labview Version 2022 Update q3_patch4
Ni ≫ Labview Version 2023 Update q1
Ni ≫ Labview Version 2023 Update q3
Ni ≫ Labview Version 2023 Update q3_patch1
Ni ≫ Labview Version 2023 Update q3_patch2
Ni ≫ Labview Version 2023 Update q3_patch3
Ni ≫ Labview Version 2023 Update q3_patch4
Ni ≫ Labview Version 2023 Update q3_patch5
Ni ≫ Labview Version 2024 Update q1
Ni ≫ Labview Version 2024 Update q1_patch1
Ni ≫ Labview Version 2024 Update q3
Ni ≫ Labview Version 2024 Update q3_patch1
Ni ≫ Labview Version 2024 Update q3_patch2
Ni ≫ Labview Version 2025 Update q1
Ni ≫ Labview Version 2025 Update q1_patch1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.19% 0.087
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
security@ni.com 7 0 0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
security@ni.com 7.3 1.3 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/dll-hijacking-vulnerability-in-ni-labview-when-loading-ni-error-reporting.html
Vendor Advisory