Security Affairs newsletter Round 475 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-4358 | Authentication Bypass by Spoofing in Progress Telerik Report Server (IIS) CVE-2024-4358 is a critical (CVSS 9.8) authentication bypass by spoofing (CWE-290) in Progress Telerik Report Server 2024 Q1 (10.0.24.305) and earlier when the server is deployed on IIS. The flaw is reachable over the network with no privileges and no user interaction, so a remote, unauthenticated attacker can spoof a valid session to reach Report Server functionality that should require sign-in; public reporting indicates this can be abused to create rogue administrator accounts and take over the instance. Access to restricted functionality and administrative control is the immediate gain, and per a released public proof of concept the bypass can be chained with the CVE-2024-1800 deserialization flaw to achieve unauthenticated remote code execution. Any organization running Telerik Report Server 2024 Q1 or earlier on IIS is affected. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-06-13, and the 97.5% EPSS score (100th percentile) signals a very high likelihood of continued exploitation, though ransomware use is listed as unknown. Do: Upgrade every Telerik Report Server instance to Progress' fixed release (2024 Q2, 10.0.24.414, or later per the vendor advisory); if prompt patching is not possible, CISA's required action is to apply vendor mitigations or discontinue use of the product. Audit the Users/Administrators list for rogue admin accounts, review IIS logs for unauthenticated requests to restricted endpoints, and inventory for any instances hosted on IIS. If your deployment is also exposed to CVE-2024-1800, patch that as well, since the public PoC chains the two flaws for unauthenticated RCE. | 9.8 | 97% | KEV |
| moderate~1,000-10,000 deployments worldwide (estimate; only a minority are internet-exposed) |
Full article420 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.
Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.
International Press – Newsletter
Cybercrime
Cybercriminals Attack Banking Customers In EU With V3B Phishing Kit
London hospital services impacted by ransomware incident
Snowflake Data Breach Impacts Ticketmaster, Other Organizations
New York Times source code stolen using exposed GitHub token
Malware
Russian Power Companies, IT Firms, and Govt Agencies Hit by Decoy Dog Trojan
RansomHub: New Ransomware has Origins in Older Knight
FBI recovers 7,000 LockBit keys, urges ransomware victims to reach out
TargetCompany’s Linux Variant Targets ESXi Environments
Hacking
Snowflake at centre of world’s largest data breach
Hacking Millions of Modems (and Investigating Who Hacked My Modem)
Molding Lies Into Reality || Exploiting CVE-2024-4358
A Zero Day TikTok Hack Is Taking Over Celebrity And Brand Accounts
2024: Old CVEs, New Targets — Active Exploitation of ThinkPHP
Intelligence and Information Warfare
Video Games Might Matter for Terrorist Financing
Disrupting FlyingYeti’s campaign targeting Ukraine
GRU’s BlueDelta Targets Key Networks in Europe with Multi-Phase Espionage Campaigns
Revealed: Russian legal foundation linked to Kremlin activities in Europe
NSA chief says China readying destructive cyberattacks on critical infrastructure
How Russia is trying to disrupt the 2024 Paris Olympic Games
Cybersecurity
Generative AI is expected to magnify the risk of deepfakes and other fraud in banking
Cyber house of cards – Politicians’ personal details exposed online
Preventing and Waging War in the AI–CYBER Era
Google Leak Reveals Thousands of Privacy Incidents
Coast Guard To Empower Maritime Cybersecurity
361 million stolen accounts leaked on Telegram added to HIBP
Cisco Patches Webex Bugs Following Exposure of German Government Meetings
How to Opt Out of Instagram and Facebook Using Your Posts for AI
How to spot a deepfake: the maker of a detection tool shares the key giveaways
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
you might also like
leave a comment
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/164292/security/security-affairs-newsletter-round-475-by-pierluigi-paganini-international-edition.html