Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-10496


An out of bounds read due to improper input validation in BuildFontMap in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions.


Published

2024-12-10T16:15:22.203

Last Modified

2025-03-04T18:35:39.467

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-1285
  • Type: Primary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ni labview ≤ 2021 Yes
Application ni labview 2022 Yes
Application ni labview 2022 Yes
Application ni labview 2022 Yes
Application ni labview 2022 Yes
Application ni labview 2023 Yes
Application ni labview 2023 Yes
Application ni labview 2023 Yes
Application ni labview 2023 Yes
Application ni labview 2023 Yes
Application ni labview 2023 Yes
Application ni labview 2024 Yes
Application ni labview 2024 Yes
Application ni labview 2024 Yes
Application ni labview 2024 Yes

References