← back
CVE-2024-23611highCWE-787

Out of Bounds Write Due to Missing Bounds Check in LabVIEW

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.8epss 0.6%
exploitation probability
0.6%top 52% of all CVEs
observed exploitation
nono source reports it
In short

LabVIEW has a flaw where it writes data outside allocated memory bounds, allowing an attacker to execute malicious code if you open a specially crafted file. This is dangerous because it gives attackers direct control over your computer.

Technical detail

An out-of-bounds write vulnerability exists due to missing bounds validation in LabVIEW's memory handling. The attack vector requires user interaction (opening a malicious VI file), but upon successful exploitation, arbitrary code execution is achieved with the privileges of the LabVIEW process. Affected versions include LabVIEW 2024 Q1 and earlier.

Summary generated and translated by AI from the official description.
An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
NI · LabVIEW