First published: Tue Jul 23 2024(Updated: )
A memory corruption issue due to an improper length check in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects NI LabVIEW 2024 Q1 and prior versions.
Credit: security@ni.com
Affected Software | Affected Version | How to fix |
---|---|---|
NI LabVIEW | <=2020 | |
NI LabVIEW | =2021 | |
NI LabVIEW | =2021-sp1 | |
NI LabVIEW | =2022-q1 | |
NI LabVIEW | =2022-q3 | |
NI LabVIEW | =2023-q1 | |
NI LabVIEW | =2023-q3 | |
NI LabVIEW | =2023-q3_patch2 | |
NI LabVIEW | =2024-q1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4081 has a high severity rating due to the potential for arbitrary code execution and information disclosure.
To fix CVE-2024-4081, you should update to the latest version of NI LabVIEW that has addressed this vulnerability.
CVE-2024-4081 affects NI LabVIEW 2024 Q1 and prior versions including 2023 Q3 and earlier.
CVE-2024-4081 is a memory corruption issue caused by an improper length check in NI LabVIEW.
An attacker can exploit CVE-2024-4081 by providing a user with a specially crafted VI file.