Out Of Bounds Write when parsing a DSB file with Digilent DASYLab
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.5epss 0.3%
exploitation probability
0.3%top 79% of all CVEs
observed exploitation
nono source reports it
There is an out of bounds write vulnerability due to improper bounds checking resulting in a large destination address when parsing a DSB file with Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References
https://www.measx.com/en/service/productsecurity/security-updates-for-measx-software/159-securityupdates/1077-deserialization-of-untrusted-data-vulnerability-in-dasylab.htmlhttps://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/memory-corruption-vulnerabilities-in-digilent-dasylab.html