Security News > 2024 > July > Critical Flaw in Telerik Report Server Poses Remote Code Execution Risk
Progress Software is urging users to update their Telerik Report Server instances following the discovery of a critical security flaw that could result in remote code execution.
The vulnerability, tracked as CVE-2024-6327, impacts Report Server version 2024 Q2 and earlier.
"In Progress Telerik Report Server versions prior to 2024 Q2, a remote code execution attack is possible through an insecure deserialization vulnerability," the company said in an advisory.
Deserialization flaws occur when an application reconstructs untrusted data that an attacker has control over without adequate validation in place, resulting in the execution of unauthorized commands.
As temporary mitigation, it's recommended to change the user for the Report Server Application Pool to one with limited permission.
The disclosure comes nearly two months after the company patched another critical shortcoming in the same software that could be abused by a remote attacker to bypass authentication and create rogue administrator users.
News URL
https://thehackernews.com/2024/07/critical-flaw-in-telerik-report-server.html
Related news
- Critical Apache Avro SDK Flaw Allows Remote Code Execution in Java Applications (source)
- Critical Linux CUPS Printing System Flaws Could Allow Remote Command Execution (source)
- Critical Flaws in Tank Gauge Systems Expose Gas Stations to Remote Attacks (source)
- Critical Zimbra RCE flaw exploited to backdoor servers using emails (source)
- Microsoft fixes Remote Desktop issues caused by Windows Server update (source)
- GitHub Patches Critical Flaw in Enterprise Server Allowing Unauthorized Instance Access (source)
- VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability (source)
- VMware fixes critical vCenter Server RCE bug – again! (CVE-2024-38812) (source)
- VMware fixes bad patch for critical vCenter Server RCE flaw (source)
- Perfctl malware strikes again as crypto-crooks target Docker Remote API servers (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-07-24 | CVE-2024-6327 | Deserialization of Untrusted Data vulnerability in Progress Telerik Report Server In Progress® Telerik® Report Server versions prior to 2024 Q2 (10.1.24.709), a remote code execution attack is possible through an insecure deserialization vulnerability. | 9.8 |