Exploit for critical Progress Telerik auth bypass released, patch now
ID: 8c0013ad-fb59-5acc-a99a-51d23d4c4c65
STIX ID: report--8c0013ad-fb59-5acc-a99a-51d23d4c4c65
Feed Name: Bleeping Computer
Threat Score
Researchers published a PoC exploit that chains an authentication bypass (CVE-2024-4358, CVSS 9.8) and a deserialization RCE (CVE-2024-1800, CVSS 8.8) in Progress Telerik Report Server to achieve remote code execution; Progress has released patches (upgrade to 10.1.24.514 or later) and advises administrators to apply updates and review local user accounts for unexpected additions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
