Progress warns Telerik Report Server has a critical security bug

Red padlock open on electric circuits network dark red background
(Image credit: Shutterstock/Chor muang)

Telerik Report Server carried a high severity vulnerability which allowed threat actors to compromise endpoints. It has since been patched, and Progress Software, the company behind the product, urged its users to apply the fix immediately.

Report Server is a popular platform for handling various reporting needs in an organization, providing tools for creating, storing, scheduling, and delivering reports in different formats.

According to Progress, the software had a deserialization of untrusted data vulnerability, which allowed threat actors to run remote code execution (RCE) attacks. It is tracked as CVE-2024-6327 and carries a base score of 9.9 (critical). 

Not abused (yet)

Report Server 2024 Q2 (10.1.24.514) and earlier are impacted by the flaw, and the first patched version is 2024 Q2 (10.1.24.709).

"Updating to Report Server 2024 Q2 (10.1.24.709) or later is the only way to remove this vulnerability," Progress said in a follow-up advisory. "The Progress Telerik team strongly recommends performing an upgrade to the latest version." To check if you are vulnerable to attacks via the deserialization of untrusted data flaw, you should open up the Configuration page, select the About tab, and look for the version number. Those who are unable to apply the patch at this time, should change the Report Server Application Pool user to one with limited permissions. 

There are currently no reports of this vulnerability being exploited in the wild.

Progress Software became infamous following the major data leak incident that involved MOVEit, a managed file transfer (MFT) product. The cyberattack, which happened last year, affected thousands of organizations all over the world, resulted in numerous ransomware attacks, and even prompted the FBI to get involved. 

MOVEit is a managed file transfer solution, generally used by SMBs and enterprises to share sensitive files securely. In late May last year, the company building out the solution was tipped off on suspicious activity. A deeper investigation uncovered a major flaw in the software, which allowed threat actors abusing it to steal the data from various endpoints. The attackers - a Russian ransomware actor named Cl0p, first said that at least a hundred companies were affected and had their data stolen. Cybersecurity experts Emsisoft claim more than 2,500 firms confirmed being affected by the breach, impacting more than 64 million people. 

Via BleepingComputer

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
Avast cybersecurity
Hackers are hijacking government software to access sensitive servers
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
The best free firewall
Microsoft fixes Power Pages security flaw, tells users to be on their guard
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
Best free Linux firewalls
SonicWall tells admins to patch worrying SSLVPN flaw immediately
Latest in Security
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Coinbase targeted after recent Github attacks
hacker.jpeg
Key trusted Microsoft platform exploited to enable malware, experts warn
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Oracle
Oracle denies data breach after hacker claims to hold six million records
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
Latest in News
Cassian Andor looking nervously over his shoulder in Andor season 2
New Andor season 2 trailer has got Star Wars fans asking the same question – and it includes an ominous call back to Rogue One's official teaser
23andMe
23andMe is bankrupt and about to sell your DNA, here's how to stop that from happening
A phone showing a ChatGPT app error message
ChatGPT was down for many – here's what happened
AirPods Max with USB-C in every color
Apple's AirPods Max with USB-C will get lossless audio in April, but you'll need to go wired
A woman sitting in a chair looking at a Windows 11 laptop
It looks like Microsoft might have thought better about banishing Copilot AI shortcut from Windows 11
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard