CVE-2025-0332: Progress UI for WinForms decompression path traversal vulnerability
In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0332?
CVE-2025-0332 is considered a high severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2025-0332?
To fix CVE-2025-0332, update Telerik UI for WinForms to version 2025 Q1 (2025.1.211) or later.
What type of vulnerability is CVE-2025-0332?
CVE-2025-0332 is a path traversal vulnerability that can lead to unauthorized access to restricted directories.
Which versions of Telerik UI for WinForms are affected by CVE-2025-0332?
All versions of Telerik UI for WinForms prior to 2025 Q1 (2025.1.211) are affected by CVE-2025-0332.
What are the potential impacts of CVE-2025-0332?
The potential impacts of CVE-2025-0332 include unauthorized disclosure or modification of sensitive files stored in restricted directories.