CVE-2025-7849: Memory Corruption Issue in NI LabVIEW due to improper error handling
A memory corruption vulnerability due to improper error handling when a VILinkObj is null exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7849?
CVE-2025-7849 is considered critical as it may lead to arbitrary code execution.
How do I fix CVE-2025-7849?
Fixing CVE-2025-7849 involves updating to a patched version of NI LabVIEW released after 2025 Q1.
What software is affected by CVE-2025-7849?
CVE-2025-7849 affects NI LabVIEW versions up to 2025 Q1.
What can an attacker achieve by exploiting CVE-2025-7849?
An attacker can execute arbitrary code on the system by getting a user to open a specially crafted VI.
What is the cause of CVE-2025-7849?
CVE-2025-7849 is caused by a memory corruption vulnerability due to improper error handling when a VILinkObj is null.