First published: Mon Dec 16 2024(Updated: )
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Telerik UI for WPF | <24.4.1213 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-10095 has a high severity rating due to its potential to allow remote code execution.
To mitigate CVE-2024-10095, upgrade to Telerik UI for WPF version 2024 Q4 (2024.4.1213) or later.
CVE-2024-10095 is caused by insecure deserialization, allowing an attacker to execute arbitrary code.
Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213) are affected by CVE-2024-10095.
As of now, there are no confirmed reports of active exploitation of CVE-2024-10095, but it poses a significant risk.