Impactful Input Validation Bug in LabVIEW Allows Arbitrary Code Execution
CVE-2024-10496

7.8HIGH

Key Information:

Vendor

Ni

Status
Vendor
CVE Published:
10 December 2024

What is CVE-2024-10496?

This vulnerability arises from an out of bounds read condition caused by improper input validation in the BuildFontMap function within fontmgr.cpp of NI LabVIEW. An attacker can exploit this weakness by providing a specially crafted VI (Virtual Instrument) to a user. Successful exploitation could potentially lead to the disclosure of sensitive information or arbitrary code execution, compromising the integrity of the system. It affects NI LabVIEW version 2024 Q3 and prior releases.

Affected Version(s)

LabVIEW Windows 0 <= 22.3.3

LabVIEW Windows 23.0 <= 23.3.4

LabVIEW Windows 24.0 <= 224.3.1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl working with CISA
.