Security advisory: DLL hijacking vulnerability in shared National Instruments components (CVE-2025-2629)
Advisory ID: ELA-SA-2026-001
Release date: June 17, 2026
Severity: Medium (CVSS 7.3)
Affected software: Elastocon Windows-based applications built on National Instruments (NI) runtimes.
Executive summary
A local DLL hijacking vulnerability (CVE-2025-2629) has been identified in the shared National Instruments (NI) LabVIEW components that are bundled with older versions of Elastocon's Windows applications.
This vulnerability is caused by an uncontrolled search path when loading the "NI Error Reporting" library. To exploit this vulnerability, an attacker must have local access to the target computer and be able to insert a malicious DLL file into the application directory or system search path. If successful, this could lead to local privilege escalation or arbitrary code execution.
Affected products and versions
This issue may affect installations of Elastocon Windows applications utilizing NI runtimes deployed prior to May 2026 using legacy installer packages for the following and prior versions:
- Arrhenius Plot: 1.0.2
- Balance: 5.3.1
- Brittleness: 1.1.0
- Compression Set: 1.7.8
- Creep Relaxation: 4.4.2
- Gehman: 1.1.1
- Hardness: 5.3.2
- Monitor: 2.0.0
- Relaxation: 2.1.0
- Resistivity: 3.0.0
- Thickness: 3.2.2
- TR: 1.3.1
- Other legacy Elastocon Windows-based testing applications installed using older packaging may also be affected.
If your software has been updated or reinstalled using our new package-based installer (identified by a teal-coloured icon of the install.exe file of the installer), your system is secure, even though the application itself will still display the version numbers listed above.
Remediation and updates
Elastocon has resolved this issue by transitioning to a new application packaging system based on National Instruments Package Manager (NIPM). The updated installers deploy the same application version but resolve the vulnerability by updating and securing the underlying, shared NI components on the system.
If you are running an affected version installed with an older packaging installer, or if your IT department’s vulnerability scanners flag this issue:
- Option A – Manual update (quickest solution): You can manually verify and update the underlying LabVIEW Runtime yourself by following the instructions below. This allows you to secure the system immediately without waiting for a new installer.
- Option B – Contact Support for a new installer: You can contact Elastocon Support to receive an updated installer which secures the system. Support contact: This email address is being protected from spambots. You need JavaScript enabled to view it.
Option A – Manual update
To ensure your system is protected against the CVE-2025-2629 vulnerability, you can manually verify the exact file version of your installed LabVIEW Runtime engine and apply the official patch directly.
Step 1: Locate the Runtime File
- Open Windows File Explorer.
- Copy and paste the following path into the address bar and press Enter:
- For 64-bit software (most common for newer deployments):
C:\Program Files\National Instruments\Shared\LabVIEW Run-Time\ - For 32-bit software (for older deployments):
C:\Program Files (x86)\National Instruments\Shared\LabVIEW Run-Time\
- For 64-bit software (most common for newer deployments):
- Open the folder corresponding to your software's release year (e.g. 2024, 2023). If you are unsure and have multiple folders here, you can repeat for each folder.
- Locate the file named lvrt.dll.
Step 2: Check the File version
- Right-click on lvrt.dll and select Properties.
- Navigate to the Details tab.
- Look at the value next to File version or Product version.
Step 3: Determine your security status
Compare your version number to the requirements below:
- LabVIEW 2024 Q3: You are safe if the version is 24.3.3 (Patch 3) or higher.
- LabVIEW 2023 Q3: You are safe if the version is 23.3.6 (Patch 6) or higher.
- LabVIEW 2022 Q3: You are safe if the version is 22.3.5 (Patch 5) or higher.
- LabVIEW 2021 or older: These versions have reached End of Life (EOL) and do not receive official security patches from NI. Please contact Elastocon to discuss upgrade options.
Direct action (if vulnerable)
If your file version is equal or lower than the affected versions listed above, you can download and run the standalone runtime update directly from National Instruments:
Download secure LabVIEW Runtime from the official NI portal
(Select your specific release year and download the latest available patch. Note: National Instruments requires a free user profile/login to download files from their portal).