Improper Error Handling Issue in LabVIEW
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
In short
LabVIEW has a flaw in how it handles errors that can allow an attacker to run malicious code on a victim's computer if they trick the user into opening a specially crafted file. This affects LabVIEW 2024 Q1 and earlier versions.
Technical detail
An improper error handling vulnerability in LabVIEW allows remote code execution when a user opens a malicious VI (LabVIEW file). The attack requires social engineering to deliver the crafted VI to a target. Versions 2024 Q1 and prior are affected.
Summary generated and translated by AI from the official description.
An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
NI · LabVIEW