There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.
History

Wed, 09 Apr 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Apr 2025 19:00:00 +0000

Type Values Removed Values Added
Description There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.
Title DLL Hijacking Vulnerability in NI LabVIEW When Loading NI Error Reporting
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NI

Published: 2025-04-09T18:45:35.434Z

Updated: 2025-04-09T18:58:49.944Z

Reserved: 2025-03-21T21:07:28.841Z

Link: CVE-2025-2629

cve-icon Vulnrichment

Updated: 2025-04-09T18:58:44.316Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-09T19:15:48.320

Modified: 2025-04-09T20:02:41.860

Link: CVE-2025-2629

cve-icon Redhat

No data.