PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-10496 NI CVE debrief

An out-of-bounds read vulnerability exists in the BuildFontMap function within National Instruments LabVIEW. This vulnerability may allow an attacker to disclose sensitive information or execute arbitrary code. The issue affects multiple versions of LabVIEW, including the 2024 release up to Q3 24.3f0, all versions of LabVIEW 2023, all versions of LabVIEW 2022, and LabVIEW 2021 and earlier versions which have reached end-of-life. National Instruments has released patches for supported versions. LabVIEW 2021 and prior versions receive no support and should be upgraded to a supported release.

Vendor
NI
Product
LabVIEW 2024
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-12-10
Original CVE updated
2024-12-10
Advisory published
2024-12-10
Advisory updated
2024-12-10

Who should care

Organizations using National Instruments LabVIEW for test, measurement, and control applications, particularly in industrial and research environments. System administrators maintaining LabVIEW deployments should prioritize patching supported versions and planning migration from end-of-life releases.

Technical summary

The vulnerability resides in the BuildFontMap function and is classified as an out-of-bounds read. Successful exploitation could result in information disclosure or arbitrary code execution. The attack vector is local, requiring user interaction, with low attack complexity and no privileges required. The vulnerability affects confidentiality, integrity, and availability with high impact ratings.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade LabVIEW 2024 installations to Q3 Patch 2 or later via NI Package Manager
  • Upgrade LabVIEW 2023 installations to Q3 Patch 5 or later via NI Package Manager
  • Upgrade LabVIEW 2022 installations to Q3 Patch 4 or later via NI Package Manager
  • Migrate LabVIEW 2021 and earlier end-of-life versions to a supported LabVIEW release
  • Review National Instruments security bulletin for additional guidance
  • Apply defense-in-depth controls for industrial control systems per CISA recommended practices

Evidence notes

CVE published 2024-12-10. CISA ICS advisory ICSA-24-345-04 published same date. CVSS 3.1 score 7.8 (HIGH).

Sources and references

Verified primary and authoritative sources

  • CVE-2024-10496 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-10496

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-10496 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-10496

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-04.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-04

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.