Lucene search

K
cvelistProgressSoftwareCVELIST:CVE-2024-0833
HistoryJan 31, 2024 - 3:15 p.m.

CVE-2024-0833 Privilege Elevation via Telerik Test Studio

2024-01-3115:15:14
CWE-269
ProgressSoftware
www.cve.org
4
privilege elevation
telerik test studio
cve-2024-0833
vulnerability
installer component

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS

0.001

Percentile

25.9%

In Telerik Test Studio versions prior to

v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component.  In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.

CNA Affected

[
  {
    "defaultStatus": "affected",
    "modules": [
      "Telerik Test Studio Installer"
    ],
    "product": "Telerik Test Studio",
    "vendor": "Progress Software",
    "versions": [
      {
        "lessThan": "v2023.3.1330",
        "status": "affected",
        "version": "2011.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

EPSS

0.001

Percentile

25.9%

Related for CVELIST:CVE-2024-0833