Skip to content

Progress Software Telerik Reporting ObjectReader Vulnerability - 20240426003

Overview

Progress Telerik has released a security advisory to address insecure deserialization vulnerability in Telerik Reporting product. The specific flaw exists within the ObjectReader class. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.

What is vulnerable?

Product Affected CVE Severity CVSS
Telerik Reporting 2024 Q1 all versions before 18.0.24.130 CVE-2024-1856, cve-2024-1801 High 8.5

What has been observed?

There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of one month... (refer Patch Management):

Additional References