NI FlexLogger URI File Parsing Vulnerability Exposes Risk for Remote Code Execution
CVE-2025-2449
7.8HIGH
What is CVE-2025-2449?
The NI FlexLogger software contains a serious vulnerability linked to the usiReg component's URI file parsing functionality. This issue arises from the inadequate validation of user-supplied file paths before they are utilized in sensitive file operations. As a result, malicious actors can potentially create arbitrary files on affected installations, targeting users to unwittingly visit compromised URLs or open harmful files. This opens the door to executing code in the context of the current user, posing significant security risks.
Affected Version(s)
FlexLogger 2024 Q1