PT-2024-16318 · National Instruments · Ni Labview

Michael Heinzl

·

Published

2024-12-10

·

Updated

2025-03-04

·

CVE-2024-10496

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NI LabVIEW versions prior to 2024 Q3
Description The issue is related to an out of bounds read due to improper input validation in the BuildFontMap function in fontmgr.cpp. This could potentially disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI.
Recommendations For versions prior to 2024 Q3, update the software to version 2024 Q3 to fix the issue. As a temporary workaround, consider restricting the use of specially crafted VI files to minimize the risk of exploitation.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10496

Affected Products

Ni Labview