CVE-2024-10095: Progress UI for WPF format provider unsafe deserialization vulnerability
Published Dec 16, 2024
·Updated
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.
Affected Software
1 affected component
Telerik UI for WPF<24.4.1213
Event History
Dec 16, 2024
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-10095?
CVE-2024-10095 has a high severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2024-10095?
To mitigate CVE-2024-10095, upgrade to Telerik UI for WPF version 2024 Q4 (2024.4.1213) or later.
3
What causes the vulnerability CVE-2024-10095?
CVE-2024-10095 is caused by insecure deserialization, allowing an attacker to execute arbitrary code.
4
Which versions of Telerik UI for WPF are affected by CVE-2024-10095?
Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213) are affected by CVE-2024-10095.
5
Is CVE-2024-10095 being actively exploited?
As of now, there are no confirmed reports of active exploitation of CVE-2024-10095, but it poses a significant risk.