CVE-2024-10012: Progress UI for WPF format provider unsafe deserialization vulnerability
Published Nov 13, 2024
·Updated
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111), a code execution attack is possible through an insecure deserialization vulnerability.
Affected Software
1 affected component
Telerik UI for WPF<2024.4.1111
Event History
Nov 13, 2024
CVE Published
via MITRE·03:19 PM
Data Sourced
via MITRE·03:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10012?
CVE-2024-10012 is rated as a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2024-10012?
To fix CVE-2024-10012, upgrade your Telerik UI for WPF to version 2024 Q4 (2024.4.1111) or later.
3
What versions of Telerik UI for WPF are affected by CVE-2024-10012?
CVE-2024-10012 affects all Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1111).
4
Can CVE-2024-10012 be exploited remotely?
Yes, CVE-2024-10012 can be exploited remotely through this insecure deserialization vulnerability.
5
What is the nature of the vulnerability in CVE-2024-10012?
CVE-2024-10012 is an insecure deserialization vulnerability that allows for code execution attacks.