CVE-2024-4200: Progress Telerik Reporting Local Deserialization Vulnerability
In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Telerik Reportingto a version that resolves this vulnerability.Fixed in 18.1.24.2.514
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4200?
CVE-2024-4200 is classified as a critical vulnerability due to its potential for code execution.
How do I fix CVE-2024-4200?
To fix CVE-2024-4200, upgrade to Progress Telerik Reporting version 2024 Q2 (18.1.24.2.514) or later.
Who is affected by CVE-2024-4200?
CVE-2024-4200 affects all users of Progress Telerik Reporting versions prior to 2024 Q2.
What type of attack is possible with CVE-2024-4200?
CVE-2024-4200 allows local threat actors to execute arbitrary code through insecure deserialization.
Is there a workaround for CVE-2024-4200?
There are no known workarounds for CVE-2024-4200; upgrading is the recommended solution.