CVE-2024-10495: Out of bounds read when loading the font table in fontmgr.cpp in NI LabVIEW
An out of bounds read due to improper input validation when loading the font table in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10495?
CVE-2024-10495 is rated as a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-10495?
To mitigate CVE-2024-10495, users should update to the latest version of NI LabVIEW beyond 2024 Q3.
What is the impact of CVE-2024-10495?
The impact of CVE-2024-10495 can include unauthorized information disclosure and possible arbitrary code execution.
Who is affected by CVE-2024-10495?
CVE-2024-10495 affects users running NI LabVIEW versions up to, but not including, 2024 Q3.
What type of vulnerability is CVE-2024-10495?
CVE-2024-10495 is classified as an out of bounds read vulnerability caused by improper input validation.