Progress Telerik Reporting Local Deserialization Vulnerability
Vulnerability Description
In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1801
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- HackerOne: 07842c0e165d4d2d8733dd4eab48b3ed0f7afe38 working with Trend Micro Zero Day Initiative
References
More from Progress Software Corporation
View All →Affected Vendor
Progress Software Corporation
View all reports →