CVE-2024-23611: Out of Bounds Write Due to Missing Bounds Check in LabVIEW
Published Mar 11, 2024
·Updated
An out of bounds write due to a missing bounds check in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.
Affected Software
11 affected components
NI LabVIEW<=2020
NI LabVIEW=2021
NI LabVIEW=2021-sp1
NI LabVIEW=2022-q1
NI LabVIEW=2022-q3
NI LabVIEW=2023-q1
NI LabVIEW=2023-q3
NI LabVIEW=2023-q3_patch1
NI LabVIEW=2023-q3_patch2
NI LabVIEW=2024-q1
National Instruments LabVIEW<2024 Q1
Event History
Mar 11, 2024
CVE Published
via MITRE·03:14 PM
Data Sourced
via MITRE·03:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-23611?
CVE-2024-23611 has been assessed as a high severity vulnerability which can lead to remote code execution.
2
How do I fix CVE-2024-23611?
To fix CVE-2024-23611, users should upgrade to the latest version of LabVIEW beyond 2024 Q1.
3
What are the potential impacts of CVE-2024-23611?
The potential impact of CVE-2024-23611 includes unauthorized remote code execution on affected systems.
4
Which versions of LabVIEW are affected by CVE-2024-23611?
CVE-2024-23611 affects LabVIEW 2024 Q1 and all prior versions.
5
How can an attacker exploit CVE-2024-23611?
An attacker can exploit CVE-2024-23611 by providing a user with a specially crafted VI that triggers the out of bounds write.