Remote Code Execution Vulnerability in LabVIEW
CVE-2024-23608

7.8HIGH

Key Information:

Vendor

Ni

Status
Vendor
CVE Published:
11 March 2024

What is CVE-2024-23608?

An out of bounds write vulnerability has been identified in LabVIEW due to a missing bounds check. This flaw may allow an attacker to exploit the vulnerability by delivering a specially crafted Virtual Instrument (VI) to a user. If successful, this exploitation can lead to the execution of arbitrary code on the affected system. The vulnerability impacts LabVIEW 2024 Q1 and all earlier versions, necessitating urgent attention from users of this software.

Affected Version(s)

LabVIEW Windows 0 <= 2024 Q1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.