CVE-2024-11948

GFI Archiver Telerik Web UI Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GFI Archiver. Authentication is not required to exploit this vulnerability. The specific flaw exists within the product installer. The issue results from the use of a vulnerable version of Telerik Web UI. An attacker can leverage this vulnerability to execute code in the context of NETWORK SERVICE. Was ZDI-CAN-24041.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:gfi:archiver:*:*:*:*:*:*:*:*

History

13 Dec 2024, 19:32

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Gfi
Gfi archiver
References () https://www.zerodayinitiative.com/advisories/ZDI-24-1671/ - () https://www.zerodayinitiative.com/advisories/ZDI-24-1671/ - Third Party Advisory
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:gfi:archiver:*:*:*:*:*:*:*:*

12 Dec 2024, 01:40

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-12 01:40

Updated : 2024-12-13 19:32


NVD link : CVE-2024-11948

Mitre link : CVE-2024-11948


JSON object : View

Products Affected

gfi

  • archiver