Privilege Elevation via Telerik Reporting Installer
CVE-2024-0832

7.8HIGH

Key Information:

Vendor
CVE Published:
31 January 2024

Summary

A privilege elevation vulnerability exists in the installer component of Telerik Reporting, affecting versions prior to 2024 R1. In environments with an existing installation of Telerik Reporting, a lower-privileged user can manipulate the installation package to gain elevated privileges on the underlying operating system. This vulnerability poses a significant risk, allowing unauthorized access to system resources and potentially compromising sensitive information, necessitating immediate attention from users and administrators of affected versions.

Affected Version(s)

Telerik Reporting 1.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Lockheed Martin Red Team
.