Telerik Report Server Flaw Could Let Attackers Create Rogue Admin Accounts
ID: d13cbc5f-7a6b-53bc-9be3-ab3dba3475fa
STIX ID: report--d13cbc5f-7a6b-53bc-9be3-ab3dba3475fa
Feed Name: The Hacker News
Progress Software disclosed CVE-2024-4358, a critical (CVSS 9.8) authentication-bypass vulnerability in Telerik Report Server (≤ 2024 Q1 / 10.0.24.305) that permits an unauthenticated remote attacker to create a local administrator account; a fix is available in Report Server 2024 Q2 (10.1.24.514) and temporary IIS URL Rewrite mitigations are recommended. The advisory highlights the potential to chain this flaw with a recent RCE (CVE-2024-1800) and urges customers to update and review user lists for unexpected local accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
