CVE-2017-2779
moderate-risk
Published 2017-09-05
An exploitable memory corruption vulnerability exists in the RSRC segment parsing functionality of LabVIEW 2017, LabVIEW 2016, LabVIEW 2015, and LabVIEW 2014. A specially crafted Virtual Instrument (VI) file can cause an attacker controlled looping condition resulting in an arbitrary null write. An attacker controlled VI file can be used to trigger this vulnerability and can potentially result in code execution.
Do I need to act?
-
0.66% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
NETWORK
/ HIGH complexity
Affected Vendors
References (8)
Third Party Advisory
http://www.securityfocus.com/bid/100519
Third Party Advisory
http://www.securityfocus.com/bid/100519
34
/ 100
moderate-risk
Severity
22/34 · High
Exploitability
2/34 · Minimal
Exposure
10/34 · Low