CVE-2025-0332: Progress Telerik UI For Winforms

Critical severity, CVSS 9.8. EPSS: 0.4% chance of exploitation in the next 30 days.

In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target path can lead to decompressing an archive's content into a restricted directory.

Affected products

  • Progress Telerik UI For Winforms: before 2025.1.211 (fixed in 2025.1.211)

Published 2025-02-12. Last modified 2026-06-17.