Description
There is a deserialization of untrusted data vulnerability in Digilent DASYLab. This vulnerability may result in arbitrary code execution. Successful exploitation requires an attacker to get a user to open a specially crafted DSB file. The vulnerability affects all versions of DASYLab.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
Any version
Credits
kimiya working with Trend Micro Zero Day Initiative
References
www.ni.com/...ption-vulnerabilities-in-digilent-dasylab.html