ZDI-CAN-21906: ZDI-24-456: NI FlexLogger FLXPROJ File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI FlexLogger. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-4044.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21906?
The CVSS rating assigned to ZDI-CAN-21906 is 7, indicating a high severity level.
How do I fix ZDI-CAN-21906?
To mitigate ZDI-CAN-21906, ensure that you have installed the latest updates and patches provided by National Instruments for FlexLogger.
What type of attacks can exploit ZDI-CAN-21906?
ZDI-CAN-21906 can be exploited by remote attackers through the execution of arbitrary code when a user interacts with a malicious webpage or file.
Who is affected by ZDI-CAN-21906?
Users of National Instruments FlexLogger are affected by ZDI-CAN-21906 if they do not follow security best practices.
Is user interaction required to exploit ZDI-CAN-21906?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file for the exploitation to occur.