First published: Wed Feb 12 2025(Updated: )
In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.
Credit: security@progress.com
Affected Software | Affected Version | How to fix |
---|---|---|
Progress Telerik UI for WinForms | <2025.1.211 | |
Progress Telerik UI for WinForms | <2025.1.211 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0332 is considered a high severity vulnerability due to its potential to allow unauthorized file access.
To fix CVE-2025-0332, update Telerik UI for WinForms to version 2025 Q1 (2025.1.211) or later.
CVE-2025-0332 is a path traversal vulnerability that can lead to unauthorized access to restricted directories.
All versions of Telerik UI for WinForms prior to 2025 Q1 (2025.1.211) are affected by CVE-2025-0332.
The potential impacts of CVE-2025-0332 include unauthorized disclosure or modification of sensitive files stored in restricted directories.