Progress warns of critical RCE bug in Telerik Report Server

Share:

Progress Software has warned customers to patch a critical remote code execution security flaw in the Telerik Report Server that can be used to compromise vulnerable devices.

As a server-based reporting platform, Telerik Report Server provides centralized storage for reports and the tools needed to create, deploy, deliver, and manage them across an organization.

Tracked as CVE-2024-6327, the vulnerability is due to a deserialization of untrusted data weakness that attackers can exploit to gain remote code execution on unpatched servers.

The vulnerability impacts Report Server 2024 Q2 (10.1.24.514) and earlier and was patched in version 2024 Q2 (10.1.24.709).

“Updating to Report Server 2024 Q2 (10.1.24.709) or later is the only way to remove this vulnerability,” the business software maker warned in a Wednesday advisory. “The Progress Telerik team strongly recommends performing an upgrade to the latest version.”

Admins can check if their servers are vulnerable to attacks by going through these steps:

  1. Go to your Report Server web UI and log in using an account with administrator rights
  2. Open the Configuration page (~/Configuration/Index).
  3. Select the About tab and the version number will be displayed in the pane on the right.

Progress also provides temporary mitigation measures for those who can’t immediately upgrade their devices to the latest release.

This requires changing the Report Server Application Pool user to one with limited permissions. Those who don’t already have a procedure for creating IIS users and assigning App Pool can follow the information in this Progress support document.

Older Telerik flaws under attack

While Progress has yet to share if CVE-2024-6327 has been exploited in the wild, other Telerik vulnerabilities have been under attack in recent years.

For instance, in 2022, a U.S. federal agency’s Microsoft Internet Information Services (IIS) web server was hacked by exploiting the CVE-2019-18935 critical Progress Telerik UI vulnerability, which is included in the FBI’s list of top targeted vulnerabilities and the NSA’s top 25 security bugs abused by Chinese hackers.

According to a joint advisory from CISA, the FBI, and MS-ISAC, at least two threat groups (one of them the Vietnamese XE Group) breached the vulnerable server.

During the breach, they deployed multiple malware payloads and collected and exfiltrated information while maintaining access to the compromised network between November 2022 and early January 2023.

More recently, security researchers developed and released a proof-of-concept (PoC) exploit targeting remote code execution on Telerik Report servers by chaining a critical authentication bypass flaw (CVE-2024-4358) and a high-severity RCE (CVE-2024-1800).

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
11:42 am, Jun 20, 2025
weather icon 26°C
L: 25° | H: 27°
overcast clouds
Humidity: 54 %
Pressure: 1023 mb
Wind: 5 mph E
Wind Gust: 8 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
25° | 27°°C 0 mm 0% 11 mph 56 % 1023 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 32°°C 0.43 mm 43% 11 mph 62 % 1020 mb 0 mm/h
Sun Jun 22 10:00 pm
weather icon
17° | 26°°C 0.86 mm 86% 15 mph 87 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
14° | 23°°C 0.2 mm 20% 14 mph 80 % 1017 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 25°°C 0 mm 0% 16 mph 76 % 1017 mb 0 mm/h
Today 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 9 mph 54 % 1023 mb 0 mm/h
Today 4:00 pm
weather icon
26° | 26°°C 0 mm 0% 11 mph 48 % 1023 mb 0 mm/h
Today 7:00 pm
weather icon
22° | 23°°C 0 mm 0% 11 mph 46 % 1022 mb 0 mm/h
Today 10:00 pm
weather icon
20° | 20°°C 0 mm 0% 8 mph 56 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 62 % 1020 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 60 % 1019 mb 0 mm/h
Tomorrow 7:00 am
weather icon
21° | 21°°C 0 mm 0% 6 mph 54 % 1019 mb 0 mm/h
Tomorrow 10:00 am
weather icon
28° | 28°°C 0 mm 0% 9 mph 34 % 1018 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,212.21
0.95%
Ethereum(ETH)
€2,221.05
0.48%
Tether(USDT)
€0.87
-0.01%
XRP(XRP)
€1.89
0.29%
Solana(SOL)
€128.91
1.33%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.148233
0.00%
Shiba Inu(SHIB)
€0.000010
0.82%
Pepe(PEPE)
€0.000009
-0.72%
Scroll to Top