CVE Feed

    Dashboard / CVE / CVE-2017-2775

    CVE-2017-2775

    An exploitable memory corruption vulnerability exists in the LvVariantUnflatten functionality in 64-bit versions of LabVIEW before 2015 SP1 f7 Patch and 2016 before f2 Patch. A specially crafted VI file can cause a user controlled value to be used as a loop terminator resulting in internal heap corruption. An attacker controlled VI file can be used to trigger this vulnerability, exploitation could lead to remote code execution.

    Published:Mar 31, 2017
    Last Modified:Apr 20, 2025
    EPS:Mar 31, 2017
    EPSS Score:0.00868
    CVSS Score:7.5

    Affected Products

    Vendor
    Ni
    Product
    Labview

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High