CVE-2017-2779Out-of-bounds Write in Instruments Labview 2016

Severity
7.8HIGHNVD
EPSS
0.7%
top 28.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 5
Latest updateMay 13

Description

An exploitable memory corruption vulnerability exists in the RSRC segment parsing functionality of LabVIEW 2017, LabVIEW 2016, LabVIEW 2015, and LabVIEW 2014. A specially crafted Virtual Instrument (VI) file can cause an attacker controlled looping condition resulting in an arbitrary null write. An attacker controlled VI file can be used to trigger this vulnerability and can potentially result in code execution.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDni/labview4 versions+3

Patches

🔴Vulnerability Details

1
GHSA
GHSA-53vp-wxjp-8gw8: An exploitable memory corruption vulnerability exists in the RSRC segment parsing functionality of LabVIEW 2017, LabVIEW 2016, LabVIEW 2015, and LabVI2022-05-13

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Code Execution Vulnerability in LabVIEW2017-08-29
Talos
Vulnerability Spotlight: Code Execution Vulnerability in LabVIEW2017-08-29
CVE-2017-2779 — Out-of-bounds Write | cvebase