Out-of-bounds Read Vulnerability in LabVIEW Could Lead to Information Disclosure or Code Execution
CVE-2024-10495

7.8HIGH

Key Information:

Vendor

Ni

Status
Vendor
CVE Published:
10 December 2024

What is CVE-2024-10495?

An out of bounds read vulnerability has been identified in NI LabVIEW due to improper input validation occurring during the loading of the font table in fontmgr.cpp. This flaw may allow an attacker to disclose sensitive information or potentially execute arbitrary code. To exploit this vulnerability, an attacker must provide a user with a specially crafted LabVIEW VI. The vulnerability impacts LabVIEW 2024 Q3 and earlier versions, making it crucial for users to apply necessary security updates and patches.

Affected Version(s)

LabVIEW Windows 0 <= 22.3.3

LabVIEW Windows 23.0 <= 23.3.4

LabVIEW Windows 24.0 <= 24.3.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl working with CISA
.