8.5

CVE-2025-7361

Medienbericht

A code injection vulnerability due to an improper initialization check exists in NI LabVIEW that may result in arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI using a CIN node.  This vulnerability affects 32-bit NI LabVIEW 2025 Q1 and prior versions.  LabVIEW 64-bit versions do not support CIN nodes and are not affected.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NiLabview Version <= 2021
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2022 Updateq1
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2022 Updateq3
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2022 Updateq3_patch1
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2022 Updateq3_patch2
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2022 Updateq3_patch4
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2022 Updateq3_patch5
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2023 Updateq1
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2023 Updateq3
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2023 Updateq3_patch1
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2023 Updateq3_patch2
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2023 Updateq3_patch3
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2023 Updateq3_patch4
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2023 Updateq3_patch5
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2023 Updateq3_patch6
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2024 Updateq1
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2024 Updateq1_patch1
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2024 Updateq3
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2024 Updateq3_patch1
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2024 Updateq3_patch2
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2024 Updateq3_patch3
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2025 Updateq1
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2025 Updateq1_patch1
   MicrosoftWindows Version- HwPlatformx86
NiLabview Version2025 Updateq1_patch2
   MicrosoftWindows Version- HwPlatformx86
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security@ni.com 8.5 0 0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
security@ni.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.