Privilege Elevation via Telerik Reporting Installer
CVE-2024-0832
7.8HIGH
Summary
A privilege elevation vulnerability exists in the installer component of Telerik Reporting, affecting versions prior to 2024 R1. In environments with an existing installation of Telerik Reporting, a lower-privileged user can manipulate the installation package to gain elevated privileges on the underlying operating system. This vulnerability poses a significant risk, allowing unauthorized access to system resources and potentially compromising sensitive information, necessitating immediate attention from users and administrators of affected versions.
Affected Version(s)
Telerik Reporting 1.0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database
Credit
Lockheed Martin Red Team