From Saturday, Nov 23rd 7:00 PM CST - Sunday, Nov 24th 7:45 AM CST, ni.com will undergo system upgrades that may result in temporary service interruption.
We appreciate your patience as we improve our online experience.
From Saturday, Nov 23rd 7:00 PM CST - Sunday, Nov 24th 7:45 AM CST, ni.com will undergo system upgrades that may result in temporary service interruption.
We appreciate your patience as we improve our online experience.
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access. These vulnerabilities affect SystemLink Server 2023 Q3 and prior versions as well as other NI products that install one or more of these services. Refer to the Affected Products section for a complete list.
These vulnerabilities are identified as CVE-2024-1155 and CVE-2024-1156.
NI strongly recommends upgrading the affected software to mitigate this vulnerability. Refer to the Affected Products section to download the update. If upgrading is not possible, this issue may be mitigated using the following methods.
Note: Some affected products do not install every service.
Using the command line:
Using Windows Explorer
CVE-2024-1155– 7.8 - CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2024-1156– 7.8 - CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
At NI, we view the security of our products as an important part of our commitment to our customers. Go to ni.com/security to stay informed and act upon security alerts and issues.
NI would like to thank 06fe5fd2bc53027c4a3b7e395af0b850e7b8a044 working with Trend Micro Zero Day Initiative for reporting this issue and working with us on coordinated disclosure.
Product Version | Mitigation |
---|---|
SystemLink Server 2023 Q3 and prior versions | Upgrade to SystemLink Server version 2024 Q1 or later in NI Package Manager or from Software Downloads |
FlexLogger 2022 Q3 and prior | If SystemLink Server is installed: Upgrade to SystemLink Server version 2024 Q1 or later in NI Package Manager or from Software Downloads
If SystemLink Server is not installed: Apply mitigations |
G Web Development Software (All Editions) 2022 Q3 and prior | |
Static Test Software Suite 1.2 and prior | |
LabVIEW NXG 5.1 Web Module LabVIEW NXG 5.1 Real-Time Module LabVIEW NXG 5.1 Community Edition | |
Data Record AD 2.0.1 and prior | |
STS Software Bundle 21.0 and prior | |
Specification Compliance Manager 2023 Q4 and prior |