LabVIEW vulnerability allows hackers to attack your computer
If you need to use LabVIEW software to design machines or industrial devices, you should be alert when opening any VI file (virtual instrument).
LabVIEW is developed by the US company - National Instruments - is a visual programming language and a powerful system design tool used worldwide in hundreds of areas. In addition, it provides engineers with a simple environment to build measurement or control systems.
Recently, Cisco Talos Security Intelligence security researchers have discovered a serious flaw in this LabVIEW software. This vulnerability allows an attacker to execute malicious code on the destination computer and control the entire system.
- How to protect high-risk network ports?
- EternalRocks - more dangerous malicious code than WannaCry exploits up to seven NSA vulnerabilities
Defined as CVE-2017-2779, this executable code vulnerability can be activated by opening a special VI file - a file format that LabVIEW uses. This vulnerability stems from memory errors in the RSRC segment parsing function of LabVIEW.
Talos researchers explained that: A specially created LabVIEW VI file (with * .vi extension) can help an attacker control loop status and write nulls at will .
Researchers have also successfully tested the vulnerability in LabVIEW 2016 version 16.0 but National Instruments does not recognize this as a flaw and does not release a patch for this vulnerability.
Because there is no patch available, LabVIEW users have only one option to be careful when opening any VI file received via email.
You should read it
- How to Become a Musician
- Top best virtual RAM creation software on today's computer
- Detected a serious zero-day vulnerability in Microsoft Office, click the document file and it will stick
- VMware patches RCE Spring4Shell vulnerability on a wide range of products
- Warning: The risk of pneumonia from mold in the trumpet instrument
- How to create a virtual drive (Virtual Hard Disk) on Windows 10 without installing any additional software
- Facebook vulnerabilities allow users to receive millions of virtual likes
- VirtualBox and VMware: Which virtual machine software is better?
May be interested
- The new Gazer - the back door targets the ministries and embassies around the worldsecurity researchers at eset have discovered a new malware with the aim of consular offices, ministries and embassies around the world to track governments and diplomatic activities.
- A hacker in the United Kingdom found a way to temporarily encrypt the WannaCry malwarehow can fantastic hackers get back stolen data without a penny?
- Warning with 4 dangerous variants of WannaCry malwarethe malicious code wannacry crippled the worldwide network in just a few hours after it appeared. in addition, 4 variants of wannacry malicious code are equally dangerous.
- All about WannaCry, Ransomware has been confusing for the past few daysthe article will provide some knowledge about wannacry and the most important security tips you should take and share with your acquaintances to prevent computers from ransomware wannacry.
- If there is not enough ransom for the file, send an email to complain to the hacker, maybe you will get a surprise giftdue to the low income and inability to pay ransom, a victim sent an email to the hacker and received unexpected results.
- The hacker group threatened to spread the network attack tool behind WannaCrythe tool used by the hacker group to create the wannacry global cyber attack is about to be released.