CVE Published: 15/05/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: ProgressSoftware |
Vendor: Progress Software Corporation |
Product: Telerik UI for WinForms Status : PUBLISHED
CVE-2024-3892 Description
A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.
Metrics
CVSS Version: 3.1 |
Base Score: 7.2 HIGH Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* HIGH User Interaction (UI)* REQUIRED Scope (S)* CHANGED
l➤ Impact Metrics: Confidentiality Impact (C)* HIGH Integrity Impact (I)* HIGH Availability Impact (A)* HIGH
Weakness Enumeration (CWE)
CWE-ID: CWE-94 CWE Name: CWE-94 : Improper Control of Generation of Code (
Code Injection
) Source: Progress Software Corporation
Common Attack Pattern Enumeration and Classification (CAPEC)