PT-2024-16317 · National Instruments · Ni Labview

Michael Heinzl

·

Published

2024-12-10

·

Updated

2024-12-10

·

CVE-2024-10495

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NI LabVIEW versions prior to 2024 Q3
Description An out of bounds read due to improper input validation when loading the font table in fontmgr.cpp may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI.
Recommendations For versions prior to 2024 Q3, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting the use of specially crafted VIs to minimize the risk of exploitation.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2024-10495

Affected Products

Ni Labview