ZDI-25-105: NI DAQExpress LVPROJECT File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI DAQExpress. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-12741.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-105?
ZDI-25-105 has been assigned a CVSS rating of 7, indicating a high severity level.
How do I fix ZDI-25-105?
To fix ZDI-25-105, users should ensure they are using the latest version of NI DAQExpress, as updates often include security patches.
What types of attacks can exploit ZDI-25-105?
ZDI-25-105 can be exploited through remote code execution by tricking users into visiting a malicious page or opening a malicious file.
Who is affected by the ZDI-25-105 vulnerability?
Users of National Instruments DAQExpress are affected by the ZDI-25-105 vulnerability.
Is user interaction required to exploit ZDI-25-105?
Yes, user interaction is required as the target must either visit a malicious page or open a malicious file.