Researchers have published a proof-of-concept (PoC) exploit script that demonstrates how two vulnerabilities can be used for remote code execution (RCE) in Progress Telerik Report Servers.

Telerik Report Server is a report management solution that organizations use to optimize the creation, sharing, storage, distribution, and scheduling of reports.
Cybersecurity researcher Sina Kheirkha developed the exploit with the help of Soroush Dalili . A detailed report has now been published , describing the process of exploiting two bugs (one allowing authentication bypass and the other a deserialization issue), to execute code on the target.
See also: Hackers exploit new vulnerabilities in WordPress plugins
Creating fraudulent administrator accounts
The first vulnerability, which allows authentication bypass , is tracked as CVE-2024-4358 (CVSS score: 9.8) and cybercriminals can use it to create administrator accounts without checks.
After identifying and investigating the vulnerability, Kheirkhah analyzed it and discovered that the 'Register' method in the “StartupController” was accessible without authentication, allowing the creation of an administrator account even after the initial setup was complete.
Progress fixed the vulnerability with the Telerik Report Server 2024 Q2 update 10.1.24.514 on May 15.
The second vulnerability used for the chain exploit is a deserialization issue tracked as CVE-2024-1800 (CVSS score: 8.8). It allows remote attackers to execute arbitrary code on vulnerable servers.
This issue was previously discovered and reported to Progress by an anonymous researcher. The company released a security for it on March 7, 2024, via Telerik® Report Server 2024 Q1 10.0.24.305.
An attacker can send a specially crafted XML payload with a “ResourceDictionary” element to the Telerik Report Server custom deserializer.
See also: Slider Revolution: Two vulnerabilities found in WordPress plugin
Then, the special component in the payload uses the 'ObjectDataProvider' class to execute commands on the server, such as launching 'cmd.exe'.

Exploiting this vulnerability is generally complex. But a Python exploit script has now been publicly released, which cybercriminals to carry out effective attacks.
This means that organizations should apply the available updates as soon as possible (upgrade to version 10.1.24.514 or later) in order to fix the two vulnerabilities and stay safe.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Organizations should take this exploit, which targets Progress Telerik Report Servers, as a wake-up call to always prioritize applying security updates immediately. Waiting to address vulnerabilities can leave systems and sensitive data at risk.
Additionally, organizations should regularly conduct security audits and penetration tests to uncover potential vulnerabilities before attackers can exploit them. This proactive approach can help prevent such attacks in the first place.
See also: TP-Link: Critical vulnerability in Archer C5400X gaming router
Finally, it is important for organizations to adopt a strong security culture and encourage employees to report any suspicious activity or vulnerability they may encounter. With the ever-evolving cyber threat landscape, it is essential for organizations to remain vigilant and protect their systems and data. By staying informed and implementing best practices, organizations can better protect themselves from potential attacks like those on Progress Telerik Report Servers.
Source: www.bleepingcomputer.com
