First published: Fri May 10 2024(Updated: )
A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects NI FlexLogger 2024 Q1 and prior versions as well as NI InstrumentStudio 2024 Q1 and prior versions.
Credit: security@ni.com
Affected Software | Affected Version | How to fix |
---|---|---|
NI FlexLogger | <2024 Q1 | |
Native Instruments USB audio devices | <2024 Q1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4044 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2024-4044, ensure that you update NI FlexLogger and NI InstrumentStudio to the latest version released after Q1 2024.
CVE-2024-4044 can lead to remote code execution if an attacker tricks a user into opening a specially crafted project file.
CVE-2024-4044 affects NI FlexLogger and NI InstrumentStudio versions up to exclusive of 2024 Q1.
An attacker can exploit CVE-2024-4044 by persuading the victim to open a malicious project file that contains untrusted data.