Description
An out of bounds read due to improper input validation in BuildFontMap in fontmgr.cpp in NI LabVIEW may disclose information or result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted VI. This vulnerability affects LabVIEW 2024 Q3 and prior versions.
Problem types
CWE-1285 Improper Validation of Specified Index, Position, or Offset in Input
Product status
Any version
23.0 (semver)
24.0 (semver)
Credits
Michael Heinzl working with CISA
References
www.ni.com/...ounds-read-vulnerabilities-in-ni-labview-.html