ZDI-24-289: NI LabVIEW VI File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Mar 12, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-23612.
Affected Software
1 affected component
NI LabVIEW
Event History
Mar 12, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-289?
The severity of ZDI-24-289 is rated at 7.8 on the CVSS scale.
2
How do I fix ZDI-24-289?
To fix ZDI-24-289, update NI LabVIEW to the latest version provided by National Instruments.
3
What can attackers do with ZDI-24-289?
Attackers can execute arbitrary code on affected installations of NI LabVIEW.
4
Does ZDI-24-289 require user interaction to be exploited?
Yes, ZDI-24-289 requires user interaction, such as visiting a malicious page or opening a malicious file.
5
Which software is affected by ZDI-24-289?
The affected software for ZDI-24-289 is NI LabVIEW.