Threat Advisories:
Highlights of Our CISO Dinner
Upgrading struggling vulnerability management programs to Threat Exposure Management, with Host, CISO Al Lindseth formerly from Plains All American Pipeline and PWC - 6 minute podcast
0:00
0:00
👥 Play Count: Loading...

Chained Flaws in Progress Telerik Report Server Enable Unauthenticated RCE

Threat Level – Red | Vulnerability Report
Download PDF

Summary:

A proof-of-concept (PoC) exploit script has been publicly disclosed, demonstrating a chained remote code execution (RCE) vulnerability present in Progress Telerik Report Servers. This exploit leverages two vulnerabilities, CVE-2024-1800 and CVE-2024-4358, an authentication bypass, and a deserialization flaw, respectively, to execute arbitrary code on the target system.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox