CVE-2024-10494: Out of bounds read in HeapObjMapImpl.cpp in NI LabVIEW
An out of bounds read due to improper input validation in HeapObjMapImpl.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10494?
CVE-2024-10494 has a high severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2024-10494?
To fix CVE-2024-10494, update to a patched version of NI LabVIEW beyond 2024 Q3.
What software is affected by CVE-2024-10494?
CVE-2024-10494 affects NI LabVIEW versions up to but not including 2024 Q3.
What are the consequences of CVE-2024-10494 exploitation?
Exploitation of CVE-2024-10494 can lead to information disclosure or arbitrary code execution.
What conditions are necessary for CVE-2024-10494 to be exploited?
Successful exploitation of CVE-2024-10494 requires an attacker to provide a specially crafted VI to the user.