CVE-2024-23612

An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.
Configurations

No configuration.

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/improper-error-handling-issues-in-labview.html - () https://www.ni.com/en/support/security/available-critical-and-security-updates-for-ni-software/improper-error-handling-issues-in-labview.html -

10 Oct 2024, 21:15

Type Values Removed Values Added
CWE CWE-755 CWE-1285
Summary
  • (es) Una vulnerabilidad de manejo incorrecto de errores en LabVIEW puede resultar en la ejecución remota de código. La explotación exitosa requiere que un atacante proporcione al usuario un VI especialmente manipulado. Esta vulnerabilidad afecta a LabVIEW 2024 Q1 y versiones anteriores.
Summary (en) An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions. (en) An improper error handling vulnerability in LabVIEW may result in remote code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q1 and prior versions.

11 Mar 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-11 16:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-23612

Mitre link : CVE-2024-23612

CVE.ORG link : CVE-2024-23612


JSON object : View

Products Affected

No product.

CWE
CWE-1285

Improper Validation of Specified Index, Position, or Offset in Input