Description
In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.
Problem types
CWE-269 Improper Privilege Management
Product status
2011.0 (semver) before v2023.3.1330
Credits
Lockheed Martin Red Team
References
www.telerik.com/teststudio
docs.telerik.com/...otices-kb/legacy-installer-vulnerability
www.telerik.com/teststudio
docs.telerik.com/...otices-kb/legacy-installer-vulnerability