ZDI-CAN-21927: ZDI-24-1031: NI VeriStand NIVSPRJ File Parsing Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI VeriStand. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-6675.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21927?
The CVSS rating for ZDI-CAN-21927 is 7, indicating a high severity level.
How do I fix ZDI-CAN-21927?
To remediate ZDI-CAN-21927, update NI VeriStand to the latest version as provided by National Instruments.
What types of attacks can exploit ZDI-CAN-21927?
ZDI-CAN-21927 can be exploited through remote code execution if a user interacts with a malicious page or file.
Who is affected by ZDI-CAN-21927?
Any installation of NI VeriStand that is not patched against this vulnerability is at risk.
Is user interaction required to exploit ZDI-CAN-21927?
Yes, user interaction is necessary for exploiting ZDI-CAN-21927, as users must visit a malicious page or open a malicious file.