Progress warnt vor kritischem RCE-Bug in Telerik Report Server

Teilen:

Progress Software has warned customers to patch a critical remote code execution security flaw in the Telerik Report Server that can be used to compromise vulnerable devices.

As a server-based reporting platform, Telerik Report Server provides centralized storage for reports and the tools needed to create, deploy, deliver, and manage them across an organization.

Tracked as CVE-2024-6327, the vulnerability is due to a deserialization of untrusted data weakness that attackers can exploit to gain remote code execution on unpatched servers.

The vulnerability impacts Report Server 2024 Q2 (10.1.24.514) and earlier and was patched in version 2024 Q2 (10.1.24.709).

“Updating to Report Server 2024 Q2 (10.1.24.709) or later is the only way to remove this vulnerability,” the business software maker warned in a Wednesday advisory. “The Progress Telerik team strongly recommends performing an upgrade to the latest version.”

Admins can check if their servers are vulnerable to attacks by going through these steps:

  1. Go to your Report Server web UI and log in using an account with administrator rights
  2. Open the Configuration page (~/Configuration/Index).
  3. Select the About tab and the version number will be displayed in the pane on the right.

Progress also provides temporary mitigation measures for those who can’t immediately upgrade their devices to the latest release.

This requires changing the Report Server Application Pool user to one with limited permissions. Those who don’t already have a procedure for creating IIS users and assigning App Pool can follow the information in this Progress support document.

Older Telerik flaws under attack

While Progress has yet to share if CVE-2024-6327 has been exploited in the wild, other Telerik vulnerabilities have been under attack in recent years.

For instance, in 2022, a U.S. federal agency’s Microsoft Internet Information Services (IIS) web server was hacked by exploiting the CVE-2019-18935 critical Progress Telerik UI vulnerability, which is included in the FBI’s list of top targeted vulnerabilities and the NSA’s top 25 security bugs abused by Chinese hackers.

According to a joint advisory from CISA, the FBI, and MS-ISAC, at least two threat groups (one of them the Vietnamese XE Group) breached the vulnerable server.

During the breach, they deployed multiple malware payloads and collected and exfiltrated information while maintaining access to the compromised network between November 2022 and early January 2023.

More recently, security researchers developed and released a proof-of-concept (PoC) exploit targeting remote code execution on Telerik Report servers by chaining a critical authentication bypass flaw (CVE-2024-4358) and a high-severity RCE (CVE-2024-1800).

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:28 pm, Juni 22, 2025
Wetter-Symbol 22°C
L: 21° | H: 23°
broken clouds
Luftfeuchtigkeit: 62 %
Druck: 1011 mb
Wind: 17 mph SW
Windböe: 28 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
21° | 23°°C 0 mm 0% 10 mph 61 % 1011 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 23°°C 0.2 mm 20% 14 mph 80 % 1016 mb 0 mm/h
Di. Juni 24 10:00 pm
Wetter-Symbol
14° | 24°°C 0.2 mm 20% 13 mph 79 % 1016 mb 0 mm/h
Mi. Juni 25 10:00 pm
Wetter-Symbol
16° | 28°°C 0 mm 0% 11 mph 83 % 1014 mb 0 mm/h
Do. Juni 26 10:00 pm
Wetter-Symbol
16° | 24°°C 1 mm 100% 15 mph 92 % 1017 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 20°°C 0 mm 0% 10 mph 61 % 1011 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
18° | 19°°C 0 mm 0% 12 mph 70 % 1011 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
17° | 17°°C 0.2 mm 20% 13 mph 80 % 1011 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
14° | 14°°C 0.2 mm 20% 13 mph 63 % 1013 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 14 mph 42 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 13 mph 32 % 1015 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 14 mph 30 % 1014 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
21° | 21°°C 0 mm 0% 14 mph 39 % 1015 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€86,327.43
-3.67%
Ethereum(ETH)
€1,897.82
-9.01%
Fesseln(USDT)
€0.87
0.00%
XRP(XRP)
€1.71
-5.87%
Solana(SOL)
€113.12
-6.09%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.129555
-6.09%
Shiba Inu(SHIB)
€0.000009
-5.83%
Pepe(PEPE)
€0.000008
-8.46%
Peanut das Eichhörnchen(PNUT)
€0.218233
13.10%
Nach oben scrollen