CVE-2024-10013
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-10013 is a newly disclosed vulnerability affecting Telerik UI for WinForms versions before 2024 Q4 (2024.4.1113). This issue allows an attacker to execute arbitrary code through insecure deserialization. Insecure deserialization occurs when an application fails to properly validate or sanitize user input, enabling an attacker to inject malicious code during the deserialization process. Successful exploitation of this vulnerability could result in significant security risks, including data theft, system compromise, or unauthorized access. Users are strongly advised to upgrade to the latest version of Telerik UI for WinForms as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Telerik