03-14-2024 04:49 AM
I see that on the Critical and Security Updates for NI Software webpage there are a number of security updates for March. When I select the CVE-2024-23608 one it details says it applies to "LabVIEW 2024 Q1 and prior versions" and then has a link to "LabVIEW 2024 Q1 Patch 1".
The thing is we don't use LabVIEW 2024. We mainly use LabVIEW 2020 and 2012 for some projects. The question is, can/should I apply this patch to LabVIEW 2012/2020 installations? Is it compatible?
Thanks.
Solved! Go to Solution.
03-14-2024 06:57 AM - edited 03-14-2024 07:49 AM
I do not expect NI to port this to prior versions. The advisory says you need to open a specially crafted file to trigger the bug and execute code in the context of the current process. If you can get someone to open a VI, you already have that with the "run when opened" setting. (I swear I remember there was a change in recent years that you could override run when opened, but I cannot find any mention of it...)
Edit: Run when opened can be disabled from LV 2021 on: https://forums.ni.com/t5/LabVIEW-2021-Public-Beta/New-Feature-quot-Run-When-Opened-quot-Security-War...