CVE-2024-12251

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Feb 12, 2025
CWE ID 77

Summary

CVE-2024-12251 is a newly disclosed vulnerability affecting the In Progress® Telerik® UI for WinUI before the 2025 Q1 (3.0.0) release. This issue poses a command injection risk due to insufficient sanitization of hyperlink components. An attacker may exploit this vulnerability by crafting a malicious hyperlink and tricking a user into clicking it, potentially leading to arbitrary code execution and serious system compromise. Organizations using the affected version of Telerik UI for WinUI are highly recommended to upgrade to the latest release as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share