First published: Thu Aug 16 2018(Updated: )
An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE) with an embedded resource file by clicking on the resource.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Telerik JustAssembly | >=2018.1.323.2 | |
Telerik Justdecompile | >=2018.2.605.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-15122 is high (7.8).
CVE-2018-15122 affects Telerik JustAssembly versions up to and including 2018.1.323.2.
CVE-2018-15122 affects Telerik JustDecompile versions up to and including 2018.2.605.0.
Code can be executed by decompiling a compiled .NET object with an embedded resource file and clicking on the resource.
Yes, please refer to the following resources for information on fixes and patches: [link 1], [link 2].