CVE-2025-7361 Details
Description
A code injection vulnerability due to an improper initialization check exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI using a CIN node. This vulnerability affects 32-bit NI LabVIEW 2025 Q1 and prior versions. LabVIEW 64-bit versions do not support CIN nodes and are not affected.
A code injection vulnerability has been identified in 32-bit NI LabVIEW 2025 Q1 and prior versions. This vulnerability arises from an improper initialization check, allowing for arbitrary code execution. Exploitation requires an attacker to persuade a user to open a specially crafted Virtual Instrument (VI) that includes a Code Interface Node (CIN). Notably, LabVIEW 64-bit versions do not support CIN nodes and are therefore not affected.
Users are advised to upgrade to LabVIEW 2025 Q3 or later. For those using LabVIEW 2025 Q1, a patch is in progress. After upgrading, users should replace CIN nodes with Call Library Function Nodes (CLFN) for interfacing with external code. If necessary for backwards compatibility, CIN nodes can be re-enabled by modifying the configuration file, although this carries risks.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 2, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-94 | Improper Control of Generation of Code ('Code Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ni labview | <= 2021 2022 q1 2022 q3 2022 q3_patch1 2022 q3_patch2 2022 q3_patch4 2022 q3_patch5 2023 q1 2023 q3 2023 q3_patch1 2023 q3_patch2 2023 q3_patch3 2023 q3_patch4 2023 q3_patch5 2023 q3_patch6 2024 q1 2024 q1_patch1 2024 q3 2024 q3_patch1 2024 q3_patch2 2024 q3_patch3 2025 q1 2025 q1_patch1 2025 q1_patch2 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 19, 2025 | Initial Analysis | [email protected] |
| Jul 29, 2025 | New CVE Received | [email protected] |