漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Privilege Elevation via Telerik JustDecompile Installer
Vulnerability Description
In Telerik JustDecompile versions prior to 2024 R1, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik JustDecompile install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
特权管理不恰当
Vulnerability Title
Telerik JustDecompile 安全漏洞
Vulnerability Description
Telerik JustDecompile是保加利亚Telerik公司的一款免费的 .NET 反编译器和程序集浏览器。 Telerik JustDecompile 2024 R1之前版本存在安全漏洞,该漏洞源于存在权限提升漏洞,权限较低的用户能够提升其在底层操作系统上的权限。
CVSS Information
N/A
Vulnerability Type
N/A