ZDI-24-1031: NI VeriStand NIVSPRJ File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI VeriStand. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-6675.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1031?
The ZDI-24-1031 vulnerability has a CVSS rating of 7, indicating it is of medium severity.
How do I fix ZDI-24-1031?
To fix ZDI-24-1031, ensure you apply the latest security updates provided by NI for VeriStand.
What type of attacks can be performed using the ZDI-24-1031 vulnerability?
Remote attackers can execute arbitrary code if a user interacts with a malicious page or file associated with ZDI-24-1031.
Is user interaction required to exploit ZDI-24-1031?
Yes, user interaction is required for the exploitation of ZDI-24-1031.
Which software is affected by ZDI-24-1031?
The ZDI-24-1031 vulnerability affects installations of NI VeriStand.