CVE-2024-3892
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
15/05/2024
Last modified:
03/07/2025
Description
A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:progress:telerik_ui_for_winforms:*:*:*:*:*:*:*:* | 2021.1.122 (including) | 2024.2.514 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



