ZDI-24-403: Progress Software Telerik Report Server ObjectReader Deserialization of Untrusted Data Remote Code Execution Vulnerability
Published Apr 25, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Telerik Report Server. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-1800.
Affected Software
1 affected component
Progress Software Telerik Report Server
Event History
Apr 25, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-403?
The severity of ZDI-24-403 is rated at 8.8 on the CVSS scale.
2
How do I fix ZDI-24-403?
To fix ZDI-24-403, apply the latest security patches provided by Progress Software for Telerik Report Server.
3
Who is affected by ZDI-24-403?
Organizations using Progress Software Telerik Report Server are affected by ZDI-24-403.
4
What type of attack does ZDI-24-403 facilitate?
ZDI-24-403 facilitates remote code execution attacks that require authentication.
5
Is authentication required to exploit ZDI-24-403?
Yes, authentication is required to exploit the ZDI-24-403 vulnerability.