Description
A memory corruption vulnerability due to improper error handling when a VILinkObj is null exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.
Problem types
Product status
Any version
23.0.0 (semver)
24.0.0 (semver)
25.0.0 (semver) before 25.3.0
Credits
Rocco Calvi (@TecR0c) with TecSecurity working with Trend Micro Zero Day Initiative
References
www.ni.com/...-corruption-vulnerabilities-in-ni-labview.html