05-22-2013 09:26 AM
Recently there has been an announcement concerning patches to resolve Active X vulnerabilities for LabVIEW and deployed applications. From the description (http://digital.ni.com/public.nsf/websearch/507DEC9DA57A708186257B3600512623?OpenDocument&espuid=CNAT...) it appears that this only applies to apps using Active X controls.
Is this a correct assessment?
05-23-2013 07:23 PM
This announcement applies to all users regardless if they are using Active X controls in their application or not. We recommend that you install the update to ensure the security of your system.
05-23-2013 07:28 PM
05-24-2013 11:18 AM
Active X controls are not typically referred to as 'active' or 'inactive' but are a software component of Microsoft Windows used when interfacing with the internet. This site will give you more details about Active X controls and serve to provide more information on how they're used.
05-24-2013 12:35 PM
If this is an ActiveX vulnerability - Will it addressed by Microsoft in form of Security Patch or Hotfix?
05-24-2013 02:37 PM - edited 05-24-2013 02:40 PM
It's a vulnerability of some ActiveX components being installed by various NI products. Microsoft only has indirect influence on this, having developed the ActiveX technology. Even if your applications are not using any NI ActiveX component they are installed in your system anyhow and could be invoked through a carefully crafted web page when browsing the net, to allow exploiting its vulnerability. So you need to upgrade your system with the NI patch if you have any software from NI installed. This will make sure that any NI ActiveX component that is installed gets updated properly. NI will include this fix in all products that get released in the next big release cycle planned for August when NI week will start.
If you have disabled executation of ActiveX in your internet browser/internet zone, then the need to update your systems with the patch is less urgent but should still be done.
05-28-2013 12:21 PM
None of the related articles mention which version of LabVIEW are affected. Does this vulnerability go way back, just 2012, or somewhere in between? Thank you.
05-28-2013 12:43 PM
@tourofmars wrote:
None of the related articles mention which version of LabVIEW are affected. Does this vulnerability go way back, just 2012, or somewhere in between? Thank you.
It affects ActiveX components installed with any NI Software prior to the release of the patch. Bluntly- it goes way back
05-28-2013 02:59 PM
@tourofmars wrote:
None of the related articles mention which version of LabVIEW are affected. Does this vulnerability go way back, just 2012, or somewhere in between? Thank you.
Unless you are only using NI software before around 1995 you should certainly consider the patch. However if you use any software before 2005 you are likely to have much more serious trouble than this vulnerability.
05-30-2013 09:14 PM
If I have not used NI ActiveX components in MSIE or Office products would I still need to roll out this NI security update? Notably only a handful of NI ocx and dll files are affected. The fewer unecessary changes I have to make to already validated systems the better.
http://digital.ni.com/public.nsf/allkb/357C0A5B43F3FCBE86257B360050CF9E