Vulnerability Details CVE-2025-7849
A memory corruption vulnerability due to improper error handling when a VILinkObj is null exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.9%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2025-7849
-
-
cpe:2.3:a:ni:labview:16.0.0.49152
-
cpe:2.3:a:ni:labview:2012
-
cpe:2.3:a:ni:labview:2014
-
cpe:2.3:a:ni:labview:2015
-
cpe:2.3:a:ni:labview:2016
-
cpe:2.3:a:ni:labview:2017
-
cpe:2.3:a:ni:labview:2018
-
cpe:2.3:a:ni:labview:2019
-
cpe:2.3:a:ni:labview:2020
-
cpe:2.3:a:ni:labview:2021
-
cpe:2.3:a:ni:labview:2022
-
cpe:2.3:a:ni:labview:2023
-
cpe:2.3:a:ni:labview:2024
-
cpe:2.3:a:ni:labview:2025