CVE-2024-4044

EUVD-2024-32609
A deserialization of untrusted data vulnerability exists in common code used by FlexLogger and InstrumentStudio that may result in remote code execution.  Successful exploitation requires an attacker to get a user to open a specially crafted project file.  This vulnerability affects NI FlexLogger 2024 Q1 and prior versions as well as NI InstrumentStudio 2024 Q1 and prior versions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 94%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
niflexlogger
2024 ≤
𝑥
≤ 24.1
ADP
niinstrumentstudio
2024 ≤
𝑥
≤ 24.1
ADP