ZeroHour

CVE-2025-2449

large

Directory traversal RCE via URI file parsing in NI FlexLogger

CVSS 3.1
8.8 high
EPSS
34%p98
Published
()
Modified
AI analysis

NI FlexLogger — National Instruments' (now Emerson) Windows desktop data-logging software for test and measurement — has a path traversal flaw (CWE-22) in the usiReg component's parsing of URI files, where a user-supplied path is not properly validated before being used in file operations. A remote attacker must lure a FlexLogger user into visiting a malicious page or opening a malicious file, which lets the attacker create arbitrary files in attacker-chosen locations, including outside the intended directories. By writing files to those locations, the attacker can achieve remote code execution in the context of the current user (CVSS 3.1: 8.8, network vector with user interaction required). Any organization running NI FlexLogger is potentially affected; the available data does not specify affected or fixed versions, so users should consult NI/Emerson's advisory (disclosed via Trend Micro's Zero Day Initiative as ZDI-CAN-21805) for patched releases. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS rates a 33.7% probability of exploitation within 30 days (98th percentile), making timely patching advisable.

What to do: Check NI/Emerson's security advisory for CVE-2025-2449 and upgrade FlexLogger to the patched release it specifies, since the source data here does not include version details. Until patched, treat URI files from untrusted sources as untrusted and avoid opening them in FlexLogger, and have FlexLogger users avoid untrusted websites while the software is running. Given the elevated EPSS score, prioritize this fix in test-lab and production-test environments.

Affected
National Instruments (NI) FlexLogger
Estimated exposure
largelikely on the order of 10,000–100,000 workstations worldwide (estimate; no public install counts) — No public install-base figures exist for FlexLogger, so this is an order-of-magnitude estimate from deployment patterns: it is NI's (now Emerson's) specialized single-user Windows data-logging application tied to NI DAQ hardware, used…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of NI FlexLogger. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of URI files by the usiReg component. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21805.

Vendors
ni
Products
flexlogger
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.