Out of Bounds Write Due to Missing Bounds Check in LabVIEW
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
In short
LabVIEW has a flaw that allows writing data outside memory boundaries when processing specially crafted files, which could let attackers run malicious code if a user opens a compromised VI file.
Technical detail
An out-of-bounds write vulnerability due to missing bounds validation in LabVIEW allows remote code execution. The attack vector requires social engineering to deliver a malicious VI file; upon user execution, memory corruption occurs enabling arbitrary code execution. Affected versions: LabVIEW 2024 Q1 and prior.
Summary generated and translated by AI from the official description.
An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
NI · LabVIEW