ZeroHour
Security Affairspublished ()ingested @securityaffairs1

Progress Software fixed critical RCE CVE-2024

criticalVulnerability exploited in the wildimportance 60CVE-2024-6327CVE-2024-1800CVE-2024-4358

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1800
In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vuln

In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.

NVD description · AI analysis pending
8.840%
  • progress telerik report server
CVE-2024-4358
Authentication Bypass by Spoofing in Progress Telerik Report Server (IIS)

CVE-2024-4358 is a critical (CVSS 9.8) authentication bypass by spoofing (CWE-290) in Progress Telerik Report Server 2024 Q1 (10.0.24.305) and earlier when the server is deployed on IIS. The flaw is reachable over the network with no privileges and no user interaction, so a remote, unauthenticated attacker can spoof a valid session to reach Report Server functionality that should require sign-in; public reporting indicates this can be abused to create rogue administrator accounts and take over the instance. Access to restricted functionality and administrative control is the immediate gain, and per a released public proof of concept the bypass can be chained with the CVE-2024-1800 deserialization flaw to achieve unauthenticated remote code execution. Any organization running Telerik Report Server 2024 Q1 or earlier on IIS is affected. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-06-13, and the 97.5% EPSS score (100th percentile) signals a very high likelihood of continued exploitation, though ransomware use is listed as unknown.

Do: Upgrade every Telerik Report Server instance to Progress' fixed release (2024 Q2, 10.0.24.414, or later per the vendor advisory); if prompt patching is not possible, CISA's required action is to apply vendor mitigations or discontinue use of the product. Audit the Users/Administrators list for rogue admin accounts, review IIS logs for unauthenticated requests to restricted endpoints, and inventory for any instances hosted on IIS. If your deployment is also exposed to CVE-2024-1800, patch that as well, since the public PoC chains the two flaws for unauthenticated RCE.

9.897% KEV
  • Progress (Telerik) Telerik Report Server 2024 Q1 (10.0.24.305) and all earlier versions, when running on IIS
moderate~1,000-10,000 deployments worldwide (estimate; only a minority are internet-exposed)
CVE-2024-6327
In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vuln

In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability.

NVD description · AI analysis pending
9.82%
  • progress telerik report server
Full article286 words · extracted from securityaffairs.com · click to collapse

Progress Software addressed a critical remote code execution vulnerability, tracked as CVE-2024-6327, in the Telerik Report Server.

Telerik Report Server is a web-based application designed for creating, managing, and delivering reports in various formats. It provides tools for report design, scheduling, and secure delivery, allowing organizations to centralize their reporting processes.

Progress Software addressed a critical remote code execution flaw, tracked as CVE-2024-6327 (CVSS score of 9.9), in the Telerik Report Server that can be exploited to compromise vulnerable devices.

“In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability.” reads the report published by the company. “Updating to Report Server 2024 Q2 (10.1.24.709) or later is the only way to remove this vulnerability. The Progress Telerik team strongly recommends performing an upgrade to the latest version listed in the table below.”

The critical flaw is due to deserialization of untrusted data issue.

The flaw impacts Report Server 2024 Q2 (10.1.24.514) and earlier, the version 2024 Q2 (10.1.24.709) addressed the vulnerability.

To mitigate this issue temporarily, change the user for the Report Server Application Pool to one with limited permissions.

Progress has not revealed if the vulnerability CVE-2024-6327 has been exploited in the wild.

In June, researchers published a proof-of-concept (PoC) exploit code for another authentication bypass vulnerability, tracked CVE-2024-1800 (CVSS score: 8.8), on Progress Telerik Report Servers.

An unauthenticated attacker can exploit the flaw to gain access Telerik Report Server restricted functionality via an authentication bypass vulnerability.

The researchers demonstrated how to create an admin account by exploiting the bypass flaw CVE-2024-4358.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Telerik Report Server)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/166168/security/telerik-report-server-cve-2024-6327.html