CVE-2025-7361: Code Injection Vulnerability in NI LabVIEW when using CIN nodes
A code injection vulnerability due to an improper initialization check exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI using a CIN node. This vulnerability affects 32-bit NI LabVIEW 2025 Q1 and prior versions. LabVIEW 64-bit versions do not support CIN nodes and are not affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7361?
CVE-2025-7361 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2025-7361?
To mitigate CVE-2025-7361, users should update to the latest version of NI LabVIEW that resolves this vulnerability.
Who is affected by CVE-2025-7361?
CVE-2025-7361 affects users of 32-bit NI LabVIEW up to version 2025 Q1.
What type of vulnerability is CVE-2025-7361?
CVE-2025-7361 is a code injection vulnerability that arises from improper initialization checks.
What is required for an attacker to exploit CVE-2025-7361?
Successful exploitation of CVE-2025-7361 requires an attacker to convince a user to open a specially crafted virtual instrument (VI) using a CIN node.