First published: Tue Dec 10 2024(Updated: )
An out of bounds read due to improper input validation in HeapObjMapImpl.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions.
Credit: security@ni.com
Affected Software | Affected Version | How to fix |
---|---|---|
National Instruments LabVIEW | <2024 Q3 | |
<=2021 | ||
=2022-q1 | ||
=2022-q3 | ||
=2022-q3_patch1 | ||
=2022-q3_patch2 | ||
=2023-q1 | ||
=2023-q3 | ||
=2023-q3_patch1 | ||
=2023-q3_patch2 | ||
=2023-q3_patch3 | ||
=2023-q3_patch4 | ||
=2024-q1 | ||
=2024-q1_patch1 | ||
=2024-q3 | ||
=2024-q3_patch1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10494 has a high severity rating due to the potential for arbitrary code execution.
To fix CVE-2024-10494, update to a patched version of NI LabVIEW beyond 2024 Q3.
CVE-2024-10494 affects NI LabVIEW versions up to but not including 2024 Q3.
Exploitation of CVE-2024-10494 can lead to information disclosure or arbitrary code execution.
Successful exploitation of CVE-2024-10494 requires an attacker to provide a specially crafted VI to the user.