CVE-2025-2449
largeDirectory traversal RCE via URI file parsing in NI FlexLogger
NI FlexLogger — National Instruments' (now Emerson) Windows desktop data-logging software for test and measurement — has a path traversal flaw (CWE-22) in the usiReg component's parsing of URI files, where a user-supplied path is not properly validated before being used in file operations. A remote attacker must lure a FlexLogger user into visiting a malicious page or opening a malicious file, which lets the attacker create arbitrary files in attacker-chosen locations, including outside the intended directories. By writing files to those locations, the attacker can achieve remote code execution in the context of the current user (CVSS 3.1: 8.8, network vector with user interaction required). Any organization running NI FlexLogger is potentially affected; the available data does not specify affected or fixed versions, so users should consult NI/Emerson's advisory (disclosed via Trend Micro's Zero Day Initiative as ZDI-CAN-21805) for patched releases. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS rates a 33.7% probability of exploitation within 30 days (98th percentile), making timely patching advisable.
What to do: Check NI/Emerson's security advisory for CVE-2025-2449 and upgrade FlexLogger to the patched release it specifies, since the source data here does not include version details. Until patched, treat URI files from untrusted sources as untrusted and avoid opening them in FlexLogger, and have FlexLogger users avoid untrusted websites while the software is running. Given the elevated EPSS score, prioritize this fix in test-lab and production-test environments.
| National Instruments (NI) FlexLogger | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NI FlexLogger usiReg URI File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of NI FlexLogger. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of URI files by the usiReg component. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-21805.
- Vendors
- ni
- Products
- flexlogger
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.