Available Security Updates for NI Software: 2025

Overview

This page provides information about published security advisories for NI software in 2025. Click the link in the Info Code column to obtain more information or to download the update.

Contents

September Security Updates

 

August Security Updates

 

July Security Updates

 

May Security Updates

 

April Security Updates

 

January Security Updates

 

NameTypeDescriptionInfo Code
NI Security Update for CVE-2024-12740SoftwareNI’s vision related software uses a third-party library for image processing that exposes several vulnerabilities.  These vulnerabilities may result in arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted file.CVE-2024-12740
NameTypeDescriptionInfo Code
NI Security Update for CVE-2025-2631 and CVE-2025-2632SoftwareThere are two out of bounds write vulnerabilities due to improper bounds checking that exist in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.CVE-2025-2631 and CVE-2025-2632
NI Security Update for CVE-2025-2630SoftwareThere is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW.  This vulnerability may result in arbitrary code execution.  Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path. CVE-2025-2630
NI Security Update for CVE-2025-2629SoftwareThere is a DLL hijacking vulnerability due to an uncontrolled search path that exists in NI LabVIEW when loading NI Error Reporting.  This vulnerability may result in arbitrary code execution.  Successful exploitation requires an attacker to insert a malicious DLL into the uncontrolled search path.CVE-2025-2629
NameTypeDescriptionInfo Code
NI Security Update for CVE-2025-30417, CVE-2025-30418, CVE-2025-30419, CVE-2025-30420, and CVE-2025-30421SoftwareThere are several memory corruption vulnerabilities due to improper bounds checking that exist in the Symbol Editor included with NI Circuit Design Suite.  These vulnerabilities may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted .sym file.  These vulnerabilities affect NI Circuit Design Suite 14.3.0 and prior versions.CVE-2025-30417
CVE-2025-30418
CVE-2025-30419
CVE-2025-30420
CVE-2025-30421
NameTypeDescriptionInfo Code
NI Security Update for CVE-2025-7361SoftwareA code injection vulnerability using an exposed function exists in NI LabVIEW that may result in arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI that contains a Code Interface Node (CIN).  This vulnerability affects 32-bit NI LabVIEW 2025 Q1 and prior versions.  LabVIEW 64-bit versions do not support CIN nodes and are not affected.CVE-2025-7361
NI Security Update for CVE-2025-7848 and CVE-2025-7849SoftwareThere are two memory corruption vulnerabilities due to improper error handling that exist in NI LabVIEW that may result in arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  These vulnerabilities affect NI LabVIEW 2025 Q1 and prior versions.CVE-2025-7848
CVE-2025-7849
NI Security Update for CVE-2025-2633 and CVE-2025-2634SoftwareThere are two out of bounds read vulnerabilities due to improper bounds checking that exist in NI LabVIEW that may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted VI.  These vulnerabilities affect NI LabVIEW 2025 Q1 and prior versions.CVE-2025-2633
CVE-2025-2634
NameTypeDescriptionInfo Code
NI Security Update for CVE-2025-9188, CVE-2025-9189, CVE-2025-57774, CVE-2025-57775, CVE-2025-57776, CVE-2025-57777, and CVE-2025-57778SoftwareThere are multiple vulnerabilities related to improper validation when parsing DSB files in Digilent DASYLab that may result in arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted DSB file.  These vulnerabilities affect all versions of Digilent DASYLab.CVE-2025-9188
CVE-2025-9189
CVE-2025-57774
CVE-2025-57775
CVE-2025-57776
CVE-2025-57777
CVE-2025-57778
NameTypeDescriptionInfo Code
NI Security Update for CVE-2025-2449SoftwareThere is a relative file path directory traversal vulnerability in the USI Registration tool for DataPlugins (USIReg.exe) used by NI software that may result in arbitrary code execution.  The USI Registration tool is used to install DataPlugins for use by other NI Software.  Successful exploitation requires an attacker to get a user to open a specially crafted .uri file.    CVE-2025-2449
NI Security Update for CVE-2025-10203SoftwareThere is a relative file path traversal vulnerability due to improper input validation in Digilent WaveForms that may result in arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted .DWF3WORK file.  This vulnerability affects Digilent WaveForms 3.24.3 and prior versions.CVE-2025-10203
NI Security Update for CVE-2025-6033 and CVE-2025-6034SoftwareThere are two memory corruption vulnerabilities due to improper input validation that exist in the Symbol Editor included with NI Circuit Design Suite.  These vulnerabilities may result in information disclosure or arbitrary code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted .sym file.CVE-2025-6033
CVE-2025-6034

Was this information helpful?

Yes

No