Impact
Improper input validation in NI-PAL allows a locally authenticated user to read or write arbitrary system memory, which can be leveraged to gain higher privileges on the host. This flaw can enable an attacker to compromise the integrity and confidentiality of the system, potentially resulting in full system takeover. The weakness is categorized as CWE-1285, representing an input validation error that permits memory access beyond intended bounds.
Affected Systems
The vulnerability affects NI-PAL version 26.3.0 and all earlier releases deployed on Microsoft Windows and Linux operating systems. These installations expose the input validation flaw to any user who can run or interact with the NI-PAL application locally.
Risk and Exploitability
With a CVSS score of 8.4, the bug is considered high severity. The EPSS score is not available, and the vulnerability is not currently listed in the CISA KEV catalog, indicating no widely documented exploitation yet. The attack vector is local: an authenticated user with access to the NI-PAL process can trigger the input validation failure and use the resulting memory access to elevate privileges. Exploitation requires no additional network access or remote interaction, but does need local presence on the target machine.
OpenCVE Enrichment