Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2024-1801: CWE-502 Deserialization of Untrusted Data in Progress Software Corporation Telerik Reporting

0
High
VulnerabilityCVE-2024-1801cvecve-2024-1801cwe-502
Published: Wed Mar 20 2024 (03/20/2024, 13:12:34 UTC)
Source: CVE Database V5
Vendor/Project: Progress Software Corporation
Product: Telerik Reporting

Description

In Progress® Telerik® Reporting versions prior to 2024 Q1 (18.0.24.130), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.

AI-Powered Analysis

AILast updated: 12/16/2025, 16:58:27 UTC

Technical Analysis

CVE-2024-1801 is an insecure deserialization vulnerability classified under CWE-502 affecting Progress Software Corporation's Telerik Reporting product prior to version 2024 Q1 (18.0.24.130). Deserialization vulnerabilities occur when untrusted data is deserialized without proper validation, allowing attackers to manipulate serialized objects to execute arbitrary code. In this case, a local threat actor with access to the system can exploit this vulnerability by providing crafted serialized data to the Telerik Reporting component, leading to code execution. The vulnerability requires local access and user interaction, but no privileges are necessary, which lowers the barrier for exploitation within a compromised or insider environment. The CVSS v3.1 base score is 7.7, reflecting high severity due to the potential for confidentiality breaches (full confidentiality impact), partial integrity compromise, and partial availability impact. The scope is changed, indicating that the vulnerability affects components beyond the initially vulnerable part. No public exploits have been reported yet, but the risk remains significant given the nature of deserialization flaws. Telerik Reporting is widely used for generating reports in enterprise environments, often integrated into internal applications, making local exploitation a realistic threat vector. The lack of an official patch link suggests that remediation may require upgrading to the fixed version 18.0.24.130 or later once available.

Potential Impact

For European organizations, this vulnerability poses a significant risk to internal reporting systems that utilize Telerik Reporting. Successful exploitation can lead to unauthorized code execution, potentially allowing attackers to access sensitive data, manipulate report contents, or disrupt reporting services. This can compromise confidentiality of business intelligence data, affect the integrity of reports used for decision-making, and degrade availability of reporting systems. Organizations with distributed teams or those allowing local user access to reporting servers are particularly vulnerable. The requirement for local access limits remote exploitation but insider threats or lateral movement by attackers within a network can facilitate exploitation. The impact is heightened in sectors relying heavily on reporting for compliance and operational decisions, such as finance, healthcare, and government agencies across Europe.

Mitigation Recommendations

1. Upgrade Telerik Reporting to version 2024 Q1 (18.0.24.130) or later as soon as the patch is available to eliminate the vulnerability. 2. Restrict local access to systems running Telerik Reporting to trusted and authenticated users only, minimizing the risk of local exploitation. 3. Implement strict access controls and monitoring on reporting servers to detect and prevent unauthorized local interactions. 4. Employ application whitelisting and endpoint protection solutions to detect anomalous code execution attempts. 5. Conduct regular audits of user privileges and local access permissions to ensure least privilege principles are enforced. 6. Educate internal users about the risks of executing untrusted files or data locally, reducing the chance of inadvertent exploitation. 7. Monitor logs for unusual deserialization activity or errors that could indicate attempted exploitation. 8. Consider network segmentation to isolate reporting servers from less trusted parts of the network.

Need more detailed analysis?Get Pro

Technical Details

Data Version
5.2
Assigner Short Name
ProgressSoftware
Date Reserved
2024-02-22T20:41:24.875Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 69418d769050fe8508ffb31f

Added to database: 12/16/2025, 4:48:54 PM

Last enriched: 12/16/2025, 4:58:27 PM

Last updated: 12/20/2025, 5:06:44 PM

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats