← back
CVE-2025-2631

Out of Bounds Write Vulnerability in NI LabVIEW in InitCPUInformation()

CVSS 8.5 HIGHEPSS 0.2%CWE-787
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 8.5EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
09 Apr 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Out of bounds write vulnerability due to improper bounds checking in NI LabVIEW in InitCPUInformation() that may result in information disclosure or arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted VI. This vulnerability affects NI LabVIEW 2025 Q1 and prior versions.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
NI · LabVIEW

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →