First published: Mon Feb 03 2025(Updated: )
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI Vision Development Module. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-12740.
Affected Software | Affected Version | How to fix |
---|---|---|
National Instruments Vision Development Module |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ZDI-25-077 has been assigned a high severity rating due to its ability to allow remote code execution.
To mitigate the vulnerability ZDI-25-077, users should apply the latest security updates and patches provided by NI for the Vision Development Module.
ZDI-25-077 affects installations of the NI Vision Development Module, specifically those that are not updated with security patches.
The attack vector for ZDI-25-077 requires user interaction, whereby the target must either visit a malicious webpage or open a malicious file.
If successfully exploited, ZDI-25-077 can lead to arbitrary code execution on the affected system, allowing attackers to potentially take control.