NI FlexLogger URI File Parsing Vulnerability Exposes Risk for Remote Code Execution
CVE-2025-2449

7.8HIGH

Key Information:

Vendor

Ni

Vendor
CVE Published:
18 March 2025

What is CVE-2025-2449?

The NI FlexLogger software contains a serious vulnerability linked to the usiReg component's URI file parsing functionality. This issue arises from the inadequate validation of user-supplied file paths before they are utilized in sensitive file operations. As a result, malicious actors can potentially create arbitrary files on affected installations, targeting users to unwittingly visit compromised URLs or open harmful files. This opens the door to executing code in the context of the current user, posing significant security risks.

Affected Version(s)

FlexLogger 2024 Q1

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.