Telerik Report Server Flaw Could Let Attackers Create Rogue Admin Accounts
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-1800 | In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vuln In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability. NVD description · AI analysis pending | 8.8 | 40% |
| — | ||
| CVE-2024-4358 | Authentication Bypass by Spoofing in Progress Telerik Report Server (IIS) CVE-2024-4358 is a critical (CVSS 9.8) authentication bypass by spoofing (CWE-290) in Progress Telerik Report Server 2024 Q1 (10.0.24.305) and earlier when the server is deployed on IIS. The flaw is reachable over the network with no privileges and no user interaction, so a remote, unauthenticated attacker can spoof a valid session to reach Report Server functionality that should require sign-in; public reporting indicates this can be abused to create rogue administrator accounts and take over the instance. Access to restricted functionality and administrative control is the immediate gain, and per a released public proof of concept the bypass can be chained with the CVE-2024-1800 deserialization flaw to achieve unauthenticated remote code execution. Any organization running Telerik Report Server 2024 Q1 or earlier on IIS is affected. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-06-13, and the 97.5% EPSS score (100th percentile) signals a very high likelihood of continued exploitation, though ransomware use is listed as unknown. Do: Upgrade every Telerik Report Server instance to Progress' fixed release (2024 Q2, 10.0.24.414, or later per the vendor advisory); if prompt patching is not possible, CISA's required action is to apply vendor mitigations or discontinue use of the product. Audit the Users/Administrators list for rogue admin accounts, review IIS logs for unauthenticated requests to restricted endpoints, and inventory for any instances hosted on IIS. If your deployment is also exposed to CVE-2024-1800, patch that as well, since the public PoC chains the two flaws for unauthenticated RCE. | 9.8 | 97% | KEV |
| moderate~1,000-10,000 deployments worldwide (estimate; only a minority are internet-exposed) |
Full article331 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 04, 2024Server Security / Vulnerability
Progress Software has rolled out updates to address a critical security flaw impacting the Telerik Report Server that could be potentially exploited by a remote attacker to bypass authentication and create rogue administrator users.
The issue, tracked as CVE-2024-4358, carries a CVSS score of 9.8 out of a maximum of 10.0.
"In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via an authentication bypass vulnerability," the company said in an advisory.
The shortcoming has been addressed in Report Server 2024 Q2 (10.1.24.514). Sina Kheirkhah of Summoning Team, who is credited with discovering and reporting the flaw, described it as a "very simple" bug that could be exploited by a "remote unauthenticated attacker to create an administrator user and login."
Besides updating to the latest version, Progress Software is urging customers to review their Report Server's users list for the presence of any new Local users that they may have not added.
As temporary workarounds until the patches can be applied, users are being asked to implement a URL Rewrite mitigation technique to remove the attack surface in the Internet Information Services (IIS) server.
The development arrives a little over a month after Progress remediated another high-severity flaw impacting the Telerik Report Server (CVE-2024-1800, CVSS score: 8.8) that permits an authenticated remote attacker to execute arbitrary code on affected installations.
In a hypothetical attack scenario, a malicious actor could fashion CVE-2024-4358 and CVE-2024-1800 into an exploit chain in order to sidestep authentication and execute arbitrary code with elevated privileges.
With vulnerabilities in Telerik servers actively exploited by threat actors in the past, it's imperative that users take steps to update to the latest version as soon as possible to mitigate potential threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/06/telerik-report-server-flaw-could-let.html