CVE-2024-5602
Stack-based Buffer Overflow Vulnerability in NI I/O Trace Tool
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted nitrace file.
The NI I/O Trace tool is installed as part of the NI System Configuration utilities included with many NI software products.? Refer to the NI Security Advisory for identifying the version of NI IO Trace.exe installed. The NI I/O Trace tool was also previously released as NI Spy.
Una vulnerabilidad de desbordamiento de búfer en la región stack de la memoria debido a una verificación de límites faltantes en NI I/O Trace Tool puede resultar en la ejecución de código arbitrario. La explotación exitosa requiere que un atacante proporcione al usuario un archivo nitrace especialmente manipulado. La herramienta NI I/O Trace se instala como parte de las utilidades de configuración del sistema NI incluidas con muchos productos de software de NI. Consulte el Aviso de seguridad de NI para identificar la versión de NI IO Trace.exe instalada. La herramienta NI I/O Trace también se lanzó anteriormente como NI Spy.
A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted nitrace file.
The NI I/O Trace tool is installed as part of the NI System Configuration utilities included with many NI software products. Refer to the NI Security Advisory for identifying the version of NI IO Trace.exe installed. The NI I/O Trace tool was also previously released as NI Spy.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-06-03 CVE Reserved
- 2024-07-23 CVE Published
- 2024-07-24 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-121: Stack-based Buffer Overflow
CAPEC
- CAPEC-100: Overflow Buffers
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
NI Search vendor "NI" | IO Trace Tool Search vendor "NI" for product "IO Trace Tool" | <= 24.3 Search vendor "NI" for product "IO Trace Tool" and version " <= 24.3" | en |
Affected
|