Progress warns of critical RCE bug in Telerik Report Server
ID: 94eed1a7-72a0-59aa-aef1-8cbfde2dbe7a
STIX ID: report--94eed1a7-72a0-59aa-aef1-8cbfde2dbe7a
Feed Name: Bleeping Computer
Progress Software disclosed CVE-2024-6327, a critical deserialization-based remote code execution vulnerability in Telerik Report Server affecting versions up to 2024 Q2 (10.1.24.514) and patched in 10.1.24.709; administrators are urged to upgrade immediately or apply a temporary mitigation by running the Report Server App Pool under a low-privilege account. The advisory notes related PoC exploit activity chaining other Telerik flaws, historical attacks exploiting older Telerik vulnerabilities, but does not confirm active exploitation of CVE-2024-6327 in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
