In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF.
📦
telerik_document_processing_libraries
Vendor: progress
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
0
Remote Access
Total CVEs
5
Total Indexed
Avg. EPSS
0.86%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
7.1
CVSS
Severity: HIGH
8.3
CVSS
In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access.
Severity: HIGH
6.5
CVSS
In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable.
Severity: MEDIUM