ZDI-CAN-22834: ZDI-25-080: NI Vision Builder AI JPG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NI Vision Builder AI. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-12740.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22834?
The severity of ZDI-CAN-22834 is considered critical as it allows remote attackers to execute arbitrary code.
How do I fix ZDI-CAN-22834?
To fix ZDI-CAN-22834, update to the latest version of NI Vision Builder AI provided by the vendor.
What type of attacks are possible with ZDI-CAN-22834?
ZDI-CAN-22834 allows remote code execution, which can lead to various malicious attacks if exploited.
Is user interaction required for ZDI-CAN-22834 exploitation?
Yes, user interaction is required for ZDI-CAN-22834 as the target must visit a malicious page or open a malicious file.
Which software is affected by ZDI-CAN-22834?
ZDI-CAN-22834 affects NI Vision Builder AI installations.