Progress warns of critical RCE bug in Telerik Report Server

Share:

Progress Software has warned customers to patch a critical remote code execution security flaw in the Telerik Report Server that can be used to compromise vulnerable devices.

As a server-based reporting platform, Telerik Report Server provides centralized storage for reports and the tools needed to create, deploy, deliver, and manage them across an organization.

Tracked as CVE-2024-6327, the vulnerability is due to a deserialization of untrusted data weakness that attackers can exploit to gain remote code execution on unpatched servers.

The vulnerability impacts Report Server 2024 Q2 (10.1.24.514) and earlier and was patched in version 2024 Q2 (10.1.24.709).

“Updating to Report Server 2024 Q2 (10.1.24.709) or later is the only way to remove this vulnerability,” the business software maker warned in a Wednesday advisory. “The Progress Telerik team strongly recommends performing an upgrade to the latest version.”

Admins can check if their servers are vulnerable to attacks by going through these steps:

  1. Go to your Report Server web UI and log in using an account with administrator rights
  2. Open the Configuration page (~/Configuration/Index).
  3. Select the About tab and the version number will be displayed in the pane on the right.

Progress also provides temporary mitigation measures for those who can’t immediately upgrade their devices to the latest release.

This requires changing the Report Server Application Pool user to one with limited permissions. Those who don’t already have a procedure for creating IIS users and assigning App Pool can follow the information in this Progress support document.

Older Telerik flaws under attack

While Progress has yet to share if CVE-2024-6327 has been exploited in the wild, other Telerik vulnerabilities have been under attack in recent years.

For instance, in 2022, a U.S. federal agency’s Microsoft Internet Information Services (IIS) web server was hacked by exploiting the CVE-2019-18935 critical Progress Telerik UI vulnerability, which is included in the FBI’s list of top targeted vulnerabilities and the NSA’s top 25 security bugs abused by Chinese hackers.

According to a joint advisory from CISA, the FBI, and MS-ISAC, at least two threat groups (one of them the Vietnamese XE Group) breached the vulnerable server.

During the breach, they deployed multiple malware payloads and collected and exfiltrated information while maintaining access to the compromised network between November 2022 and early January 2023.

More recently, security researchers developed and released a proof-of-concept (PoC) exploit targeting remote code execution on Telerik Report servers by chaining a critical authentication bypass flaw (CVE-2024-4358) and a high-severity RCE (CVE-2024-1800).

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:55 pm, Jun 22, 2025
weather icon 25°C
L: 24° | H: 27°
scattered clouds
Humidity: 49 %
Pressure: 1013 mb
Wind: 15 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
24° | 27°°C 0 mm 0% 17 mph 64 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 16 mph 77 % 1015 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
16° | 27°°C 0 mm 0% 9 mph 86 % 1013 mb 0 mm/h
Thu Jun 26 10:00 pm
weather icon
17° | 24°°C 1 mm 100% 15 mph 95 % 1018 mb 0 mm/h
Today 1:00 pm
weather icon
24° | 25°°C 0 mm 0% 15 mph 49 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
21° | 24°°C 0 mm 0% 17 mph 47 % 1013 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 22°°C 0 mm 0% 13 mph 54 % 1012 mb 0 mm/h
Today 10:00 pm
weather icon
16° | 16°°C 0 mm 0% 10 mph 64 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
16° | 16°°C 0 mm 0% 13 mph 76 % 1011 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0.2 mm 20% 13 mph 81 % 1011 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0.2 mm 20% 13 mph 60 % 1013 mb 0 mm/h
Tomorrow 10:00 am
weather icon
17° | 17°°C 0 mm 0% 13 mph 46 % 1014 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,111.93
-1.14%
Ethereum(ETH)
€1,972.93
-6.84%
Tether(USDT)
€0.87
0.02%
XRP(XRP)
€1.75
-5.47%
Solana(SOL)
€115.31
-6.66%
USDC(USDC)
€0.87
0.01%
Dogecoin(DOGE)
€0.134929
-4.93%
Shiba Inu(SHIB)
€0.000010
-4.95%
Pepe(PEPE)
€0.000008
-8.93%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top