Memory Corruption Issue in NI LabVIEW due to improper error handling

CVE Details

Basic Information

Title Memory Corruption Issue in NI LabVIEW due to improper error handling
Type cve
Published 2025-07-29T21:27:20.080Z
Modified 2025-07-29T21:27:20.080Z

Product Information

Vendor NI
Product LabVIEW
Version 0

CVSS Information

Base Score 7.8 (HIGH)
Attack Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Analysis

AI Description A memory corruption vulnerability in NI LabVIEW can lead to arbitrary code execution when a user opens a specially crafted VI. This issue stems from improper error handling when a VILinkObj is null. Successful exploitation requires user interaction.
AI Severity High
AI Vendor National Instruments
AI Product NI LabVIEW
AI Version 0, 23.0.0, 24.0.0, 25.0.0

Affected Products

  • NI LabVIEW 0
  • NI LabVIEW 23.0.0
  • NI LabVIEW 24.0.0
  • NI LabVIEW 25.0.0

Additional Information

CWE List CWE-1285
Source NI

Description

A memory corruption vulnerability due to improper error handling when a VILinkObj is null exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.