ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Progress fixes critical RCE flaw in Telerik Report Server, upgrade ASAP! (CVE-2024-6327)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1800
In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vuln

In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.

NVD description · AI analysis pending
8.840%
  • progress telerik report server
CVE-2024-4358
Authentication Bypass by Spoofing in Progress Telerik Report Server (IIS)

CVE-2024-4358 is a critical (CVSS 9.8) authentication bypass by spoofing (CWE-290) in Progress Telerik Report Server 2024 Q1 (10.0.24.305) and earlier when the server is deployed on IIS. The flaw is reachable over the network with no privileges and no user interaction, so a remote, unauthenticated attacker can spoof a valid session to reach Report Server functionality that should require sign-in; public reporting indicates this can be abused to create rogue administrator accounts and take over the instance. Access to restricted functionality and administrative control is the immediate gain, and per a released public proof of concept the bypass can be chained with the CVE-2024-1800 deserialization flaw to achieve unauthenticated remote code execution. Any organization running Telerik Report Server 2024 Q1 or earlier on IIS is affected. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-06-13, and the 97.5% EPSS score (100th percentile) signals a very high likelihood of continued exploitation, though ransomware use is listed as unknown.

Do: Upgrade every Telerik Report Server instance to Progress' fixed release (2024 Q2, 10.0.24.414, or later per the vendor advisory); if prompt patching is not possible, CISA's required action is to apply vendor mitigations or discontinue use of the product. Audit the Users/Administrators list for rogue admin accounts, review IIS logs for unauthenticated requests to restricted endpoints, and inventory for any instances hosted on IIS. If your deployment is also exposed to CVE-2024-1800, patch that as well, since the public PoC chains the two flaws for unauthenticated RCE.

9.897% KEV
  • Progress (Telerik) Telerik Report Server 2024 Q1 (10.0.24.305) and all earlier versions, when running on IIS
moderate~1,000-10,000 deployments worldwide (estimate; only a minority are internet-exposed)
CVE-2024-6096
In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vuln

In Progress® Telerik® Reporting versions prior to 18.1.24.709, a code execution attack is possible through object injection via an insecure type resolution vulnerability.

NVD description · AI analysis pending
9.8<1%
  • progress telerik reporting
CVE-2024-6327
In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vuln

In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability.

NVD description · AI analysis pending
9.82%
  • progress telerik report server
Full article333 words · extracted from helpnetsecurity.com · click to collapse

Progress Software has fixed a critical vulnerability (CVE-2024-6327) in its Telerik Report Server solution and is urging users to upgrade as soon as possible.

CVE-2024-6327

About CVE-2024-6327 (and CVE-2024-6096)

Telerik Report Server is an enterprise solution for storing, creating, managing and viewing reports in web and desktop applications.

CVE-2024-6327 is an insecure (untrusted data) deserialization vulnerability that may allow attackers to remotely execute code on the underlying server through CVE-2024-6096, an insecure type resolution vulnerability that affects Telerik Reporting, a tool for building reports for and adding them to web and desktop applications.

CVE-2024-6096 allows for an object injection attack. It was reported by Markus Wulftange with CODE WHITE GmbH.

Both vulnerabilities have been fixed, and Progress Software publicly disclosed their existence on Wednesday.

What to do?

Customers have been advised to upgrade to Telerik Reporting 2024 Q2 (v18.1.24.709), as it’s the only way to remove CVE-2024-6096, and to upgrade to Telerik Report Server 2024 Q2 (10.1.24.709) or later to fix CVE-2024-6327.

If the latter action is not possible, Progress Software notes that users “can temporarily mitigate this issue by changing the user for the Report Server Application Pool to one with limited permissions”.

There is no mention of the vulnerabilities being exploited in the wild and there is no known PoC available at the moment, but Progress Software’s solutions are often targeted by attackers.

We all remember the disastrous consequences of ransomware attackers leveraging a zero day in Progress Software’s MOVEit file transfer solution. But before that, various vulnerabilities in the company’s Telerik UI, a popular UI component library for .NET web applications, had been used by attackers to install web shells.

And just last month, the Shadowserver Foundation spotted exploitation attempts for CVE-2024-4358, a vulnerability that, when concatenated with CVE-2024-1800, allowed attackers to achieve unauthenticated remote code execution on Progress Telerik Report Servers.

So upgrade your installations quickly!

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/07/26/cve-2024-6327/