Progress Telerik Document Processing Libraries Arbitrary File Export Vulnerability
Vulnerability
A vulnerability exists in Progress Telerik Document Processing Libraries, in versions prior to 2025 Q1 (2025.1.205), that allows the contents of a file from an arbitrary path to be exported to RTF format. This issue is present in libraries using .NET Standard 2.0.
Impact
Exploitation of this vulnerability could lead to unauthorized access to file contents, allowing them to be exported in RTF format.
Remediation
Users are advised to upgrade to Progress Telerik Document Processing Libraries version 2025 Q1 (2025.1.2xx). Those with a Telerik license can download the update from the Telerik Product Downloads page. For guidance on upgrading, refer to the Telerik Document Processing Upgrade Instructions.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
