Arbitrary Code Execution Vulnerability in NI LabVIEW (CVE-2024-2465)
CVE-2024-10494
7.8HIGH
What is CVE-2024-10494?
A vulnerability has been identified in National Instruments' LabVIEW software that allows for an out of bounds read due to inadequate input validation in the HeapObjMapImpl.cpp component. This flaw may lead to critical information disclosure or could allow an attacker to execute arbitrary code. To exploit this vulnerability, an attacker must entice a user into opening a specially crafted Virtual Instrument (VI). The affected versions include LabVIEW 2024 Q3 and earlier, highlighting the need for immediate attention to security patches and updates.
Affected Version(s)
LabVIEW Windows 0 <= 22.3.3
LabVIEW Windows 23.0 <= 23.3.4
LabVIEW Windows 24.0 <= 24.3.1