Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access. These vulnerabilities affect SystemLink Server 2023 Q3 and prior versions as well as other NI products that install one or more of these services. Refer to the Affected Products section for a complete list.
These vulnerabilities are identified as CVE-2024-1155 and CVE-2024-1156.
NI strongly recommends upgrading the affected software to mitigate this vulnerability. Refer to the Affected Products section to download the update. If upgrading is not possible, this issue may be mitigated using the following methods.
Note: Some affected products do not install every service.
Using the command line:
Using Windows Explorer
Product Version | Mitigation |
---|---|
SystemLink Server 2023 Q3 and prior versions | Upgrade to SystemLink Server version 2024 Q1 or later in NI Package Manager or from Software Downloads |
FlexLogger 2022 Q3 and prior | If SystemLink Server is installed: Upgrade to SystemLink Server version 2024 Q1 or later in NI Package Manager or from Software Downloads
If SystemLink Server is not installed: Apply mitigations |
G Web Development Software (All Editions) 2022 Q3 and prior | |
Static Test Software Suite 1.2 and prior | |
LabVIEW NXG 5.1 Web Module LabVIEW NXG 5.1 Real-Time Module LabVIEW NXG 5.1 Community Edition | |
Data Record AD 2.0.1 and prior | |
STS Software Bundle 21.0 and prior | |
Specification Compliance Manager 2023 Q4 and prior |
CVE-2024-1155– 7.8 - CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2024-1156– 7.8 - CVSS:3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
At NI, we view the security of our products as an important part of our commitment to our customers. Go to ni.com/security to stay informed and act upon security alerts and issues.
NI would like to thank 06fe5fd2bc53027c4a3b7e395af0b850e7b8a044 working with Trend Micro Zero Day Initiative for reporting this issue and working with us on coordinated disclosure.
Help us improve your future ni.com experience.
What software will you be using with this product?