logo

Telerik Report Server Flaw Could Let Attackers Create Rogue Admin Accounts

ID: d13cbc5f-7a6b-53bc-9be3-ab3dba3475fa

STIX ID: report--d13cbc5f-7a6b-53bc-9be3-ab3dba3475fa

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2024-06-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Progress Software disclosed CVE-2024-4358, a critical (CVSS 9.8) authentication-bypass vulnerability in Telerik Report Server (≤ 2024 Q1 / 10.0.24.305) that permits an unauthenticated remote attacker to create a local administrator account; a fix is available in Report Server 2024 Q2 (10.1.24.514) and temporary IIS URL Rewrite mitigations are recommended. The advisory highlights the potential to chain this flaw with a recent RCE (CVE-2024-1800) and urges customers to update and review user lists for unexpected local accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.