CVE-2025-2630: DLL Hijacking Vulnerability in NI LabVIEW
There is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2630?
The severity of CVE-2025-2630 is critical, as it allows for arbitrary code execution due to a DLL hijacking vulnerability.
How do I fix CVE-2025-2630?
To fix CVE-2025-2630, update NI LabVIEW to a version that addresses the DLL hijacking issue.
What is the risk associated with CVE-2025-2630?
The risk associated with CVE-2025-2630 includes potential unauthorized access and control over affected systems through malicious DLLs.
Which versions of NI LabVIEW are affected by CVE-2025-2630?
NI LabVIEW versions up to but not including 2025 Q1 are affected by CVE-2025-2630.
Can CVE-2025-2630 be exploited remotely?
Yes, CVE-2025-2630 can be potentially exploited remotely if an attacker successfully places a malicious DLL in the uncontrolled search path.