CVE-2024-3892: Local code execution vulnerability in Telerik UI for WinForms
Published May 15, 2024
·Updated
A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.
Affected Software
2 affected components
Telerik UI for WinForms>=2021.1.122<2024.2.514
Progress Telerik UI for WinForms>=2021.1.122<2024.2.514
Event History
May 15, 2024
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-3892?
CVE-2024-3892 is classified as a local code execution vulnerability.
2
How do I fix CVE-2024-3892?
To fix CVE-2024-3892, upgrade Telerik UI for WinForms to version 2024.2.514 or later.
3
Who is affected by CVE-2024-3892?
CVE-2024-3892 affects users of Telerik UI for WinForms versions from 2021.1.122 to 2024.2.514.
4
What type of vulnerability is CVE-2024-3892?
CVE-2024-3892 is a local code execution vulnerability that allows untrusted theme assemblies to execute arbitrary code.
5
When was CVE-2024-3892 disclosed?
CVE-2024-3892 was disclosed as a vulnerability affecting specific versions of Telerik UI for WinForms.