CVE-2025-7361
HIGHDescription
A code injection vulnerability due to an improper initialization check exists in NI LabVIEW that may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI using a CIN node. This vulnerability affects 32-bit NI LabVIEW 2025 Q1 and prior versions. LabVIEW 64-bit versions do not support CIN nodes and are not affected.
Is your site exposed to CVE-2025-7361?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| ni | labview |
| microsoft | windows |
References
Frequently Asked Questions
What is CVE-2025-7361? +
How severe is CVE-2025-7361? +
What products are affected by CVE-2025-7361? +
How do I check if I'm vulnerable to CVE-2025-7361? +
Related Vulnerabilities
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including …
A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default …
MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/release-preparation.yml inlined attacker-controlled github.event.pull_request.title into a …
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.4, Kiota's PHP generator embedded OpenAPI description, default fields, …
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and …
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE …