In Telerik Test Studio versions prior to v2023.3.1330, a privilege elevation vulnerability has been identified in the applications installer component. In an environment where an existing Telerik Test Studio install is present, a lower privileged user has the ability to manipulate the installation package to elevate their privileges on the underlying operating system.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.telerik.com/teststudio | product |
https://docs.telerik.com/teststudio/knowledge-base/product-notices-kb/legacy-installer-vulnerability | vendor advisory |