
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2024-1800 affects Progress Telerik Report Server versions prior to 2024 Q1 (10.0.24.130). The vulnerability is an insecure deserialization flaw that enables remote code execution attacks. This critical vulnerability was discovered by an anonymous researcher working with Trend Micro's Zero Day Initiative and was disclosed in March 2024 (Telerik Advisory, ZDI Advisory).
The vulnerability exists within the ObjectReader class and stems from inadequate validation of user-supplied data, which can result in deserialization of untrusted data. The vulnerability has received a CVSS v3.1 base score of 9.9 (Critical) from Progress Software Corporation and 8.8 (High) from NIST, with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H. The vulnerability is classified as CWE-502 (Deserialization of Untrusted Data) (ZDI Advisory, NVD).
An attacker who successfully exploits this vulnerability can execute arbitrary code in the context of SYSTEM on affected installations of Progress Software Telerik Report Server. The vulnerability could potentially allow attackers to interfere with reporting functionality, understand the victim's network, or gain further access leveraging the Active Directory integration (ZDI Advisory, Help Net Security).
The vulnerability requires authentication to exploit. However, when chained with CVE-2024-4358, it becomes possible to achieve unauthenticated remote code execution. A proof-of-concept exploit combining both vulnerabilities has been publicly released, increasing the risk of active exploitation (Arctic Wolf, Help Net Security).
The only complete mitigation is to update to Report Server 2024 Q1 (10.0.24.130) or higher. Organizations should follow their standard patching and testing procedures to avoid operational impacts. Administrators are advised to review their Report Server's users list for any unauthorized new Local users at {host}/Users/Index (Telerik Advisory, Arctic Wolf).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."