First published: Wed Dec 18 2024(Updated: )
A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects DAQExpress 5.1 and prior versions. Please note that DAQExpress is an EOL product and will not receive any updates.
Credit: security@ni.com
Affected Software | Affected Version | How to fix |
---|---|---|
National Instruments DAQExpress | <5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12741 has a high severity rating due to its potential for remote code execution.
To fix CVE-2024-12741, users should update to NI DAQExpress version 5.2 or later.
CVE-2024-12741 is caused by a deserialization of untrusted data vulnerability in NI DAQExpress.
CVE-2024-12741 affects NI DAQExpress version 5.1 and all prior versions.
Yes, successful exploitation of CVE-2024-12741 can allow attackers to execute arbitrary code, potentially leading to data breaches.