CVE-2024-0832: Privilege Elevation via Telerik Reporting Installer
In Telerik Reporting versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Reporting install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0832?
CVE-2024-0832 has been classified as a privilege elevation vulnerability.
How do I fix CVE-2024-0832?
To fix CVE-2024-0832, upgrade to Telerik Reporting version 2024 R1 or later.
Who is affected by CVE-2024-0832?
CVE-2024-0832 affects users of Telerik Reporting versions prior to 2024 R1.
What type of vulnerability is CVE-2024-0832?
CVE-2024-0832 is a privilege elevation vulnerability in the applications installer component.
Can a lower privileged user exploit CVE-2024-0832?
Yes, a lower privileged user can exploit CVE-2024-0832 to manipulate the installation process.