← Back

CVE-2017-2779

nvd nist
Published: Sep 5, 2017Modified: May 13, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An exploitable memory corruption vulnerability exists in the RSRC segment parsing functionality of LabVIEW 2017, LabVIEW 2016, LabVIEW 2015, and LabVIEW 2014. A specially crafted Virtual Instrument (VI) file can cause an attacker controlled looping condition resulting in an arbitrary null write. An attacker controlled VI file can be used to trigger this vulnerability and can potentially result in code execution.

Affected (4)

Products: Ni: Labview
1 product
Labview
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Ni
Version 2014
Version 2015
Version 2016
Version 2017

References (8)

Source: talos-cna@cisco.com
MitigationVendor Advisory
Source: talos-cna@cisco.com
Third Party AdvisoryVDB Entry
Source: talos-cna@cisco.com
ExploitPatchThird Party Advisory
Source: talos-cna@cisco.com
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry

Timeline

No history available yet.