CVE-2024-3892 - CVE House
Back to Database
Status published High CVE-2024-3892

Local code execution vulnerability in Telerik UI for WinForms

Vulnerability Description

A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3892

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Progress Software Corporation

View all reports →

Affected Software

Telerik UI for WinForms
Vulnerable Versions:
v2021.1.122

Timeline

Official Publish: May 15th, 2024
Last Modified: August 1st, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Weaknesses (CWE)