Directory Path Traversal Vulnerability in NI VeriStand with vsmodel Files
No sign of exploitation. No public exploitation artifact known so far.
NI VeriStand has a flaw that lets attackers run malicious code on your computer if you open a specially crafted .vsmodel file. This happens because the program doesn't properly check file paths, allowing an attacker to access unauthorized locations on your system.
A path traversal vulnerability (CWE-22) in NI VeriStand's vsmodel file loader allows an attacker to execute arbitrary code through a crafted .vsmodel file. The attack vector is user interaction (opening the malicious file); successful exploitation requires social engineering to trick a user into opening the file, with impact including remote code execution on the affected system running VeriStand 2024 Q2 or earlier.