PT-2024-28847 · National Instruments · Ni Flexlogger+1

Kimiya

·

Published

2024-05-10

·

Updated

2024-07-06

·

CVE-2024-4044

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NI FlexLogger versions prior to 2024 Q1 NI InstrumentStudio versions prior to 2024 Q1
Description A deserialization of untrusted data issue exists in common code used by FlexLogger and InstrumentStudio, potentially resulting in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file.
Recommendations For NI FlexLogger versions prior to 2024 Q1, update to a version later than 2024 Q1 to resolve the issue. For NI InstrumentStudio versions prior to 2024 Q1, update to a version later than 2024 Q1 to resolve the issue. As a temporary workaround, consider avoiding the use of FLXPROJ file parsing until a patch is available.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2024-4044
ZDI-24-456

Affected Products

Ni Flexlogger
Ni Instrumentstudio