AI description
CVE-2024-12741 is a vulnerability found in National Instruments' DAQExpress software, specifically versions up to 5.1 on Windows. This flaw allows remote code execution by exploiting how the software handles serialized data. An attacker could gain control of a user's system if the user opens a specially crafted project file. Notably, DAQExpress is an end-of-life product and will not receive official patches. The vulnerability stems from deserialization of untrusted data, categorized as CWE-502. Exploitation could compromise system confidentiality, integrity, and availability. While the software will not receive vendor updates, mitigation strategies include avoiding untrusted files, upgrading to alternative software, using security software, and educating users about potential threats.
- Description
- A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects DAQExpress 5.1 and prior versions. Please note that DAQExpress is an EOL product and will not receive any updates.
- Source
- security@ni.com
- NVD status
- Awaiting Analysis
- CNA Tags
- unsupported-when-assigned
CVSS 4.0
- Type
- Secondary
- Base score
- 8.4
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- security@ni.com
- CWE-502
- Hype score
- Not currently trending
NI (National Instruments) DAQExpress Remote Code Execution - CVE-2024-12741 https://t.co/1JBiKO0k69
@int20z
6 Mar 2025
8926 Impressions
6 Retweets
35 Likes
13 Bookmarks
0 Replies
1 Quote
CVE-2024-12741 A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to ge… https://t.co/4RYUMAJ02z
@CVEnew
18 Dec 2024
283 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes