CVE-2024-4358 is an authentication-bypass vulnerability in Progress Telerik Report Server versions 2024 Q1 (10.0.24.305) and earlier, fixed in 2024 Q2 (10.1.24.514). In IIS deployments, the server setup registration functionality remains accessible without authentication after initial setup has completed. A remote attacker can invoke this functionality to create a new user assigned the System Administrator role, then authenticate using that account and access functionality intended only for authorized administrators.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
7 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a single Metasploit module targeting Telerik Report Server (versions 10.0.24.130 and prior) for remote code execution. The exploit chains two vulnerabilities: an authentication bypass (CVE-2024-4358) that allows unauthenticated creation of an admin user, and a .NET deserialization flaw (CVE-2024-1800) that enables arbitrary OS command execution via a maliciously crafted report file. The module automates user creation (if needed), login, report upload, payload triggering, and cleanup (removing the report but not the user). The exploit interacts with several HTTP endpoints of the Telerik Report Server web application, and is weaponized for use within the Metasploit framework. The code is written in Ruby and is structured as a standard Metasploit exploit module.
This repository contains a single Metasploit auxiliary module targeting an authentication bypass vulnerability (CVE-2024-4358) in Telerik Report Server versions 10.0.24.305 and prior. The module allows an unauthenticated attacker to create a new administrator account by exploiting the fact that the initial setup page remains accessible after setup is complete. The exploit works by sending a crafted POST request to the /Startup/Register endpoint, supplying attacker-controlled or randomly generated credentials. If successful, the module reports the new credentials and provides administrative access to the attacker. The module also includes a check action to verify if the target is vulnerable by inspecting the /Account/Login page and parsing the version from the HTML. The code is written in Ruby and is designed to be run within the Metasploit framework. No hardcoded IPs or domains are present; all endpoints are relative to the user-supplied TARGETURI. The exploit is operational and provides a direct path to administrative access on vulnerable systems.
This repository provides a working exploit for CVE-2024-4358, an authentication bypass and remote code execution vulnerability in Progress Telerik Report Server (2024 Q1 and earlier). The main exploit script (CVE-2024-4358.py) is a Python tool that automates the process of exploiting the vulnerability: it registers a new user via the /Startup/Register endpoint, obtains an authentication token from /Token, and then uploads a malicious report to /api/reportserver/report to trigger deserialization and execute arbitrary shell commands (default: 'id'). The script supports single or multiple targets, proxying, and output to file. The included YAML file (CVE-2024-4358.yaml) is a nuclei template for detection and verification of the vulnerability. The README provides usage instructions and context. The exploit is operational, providing real RCE on vulnerable targets, and is not just a detection script. The main attack vector is network-based, targeting exposed HTTP endpoints on the Telerik Report Server. No hardcoded IPs or domains are present, but the endpoints are fingerprintable. The repository is well-structured, with clear separation between exploit code, detection template, and documentation.
This repository contains a Python exploit script (CVE-2024-4358.py) targeting CVE-2024-4358, an authentication bypass and remote code execution vulnerability in Progress Telerik Report Server (version 2024 Q1 (10.0.24.305) or earlier). The exploit is operational and allows an unauthenticated attacker to execute arbitrary shell commands on the target server by abusing a deserialization flaw in the '/api/reportserver/report' endpoint. The script supports both single and multiple targets (via a list), allows proxying, and saves results (including credentials and tokens) to a file. The README provides usage instructions and context, confirming the exploit's purpose and target. No framework is used; the code is standalone and written in Python. The main attack vector is network-based, exploiting HTTP(S) endpoints exposed by the vulnerable server. The repository is well-structured, with clear separation between code, documentation, and licensing.
This repository contains a Python exploit script (CVE-2024-4358.py) and a README for a pre-authenticated remote code execution (RCE) chain targeting Progress Telerik Report Server (CVE-2024-4358 and CVE-2024-1800). The exploit works by first bypassing authentication to create a backdoor user, then logging in as that user to obtain an access token. It crafts a malicious .trdp report file containing a deserialization payload that executes an arbitrary system command (provided by the attacker). The script uploads this payload via the Report Server's API endpoints and triggers its execution, resulting in RCE. The README provides usage instructions, supported versions (2012-2024), and mitigation advice. The exploit is operational, automating the full attack chain from authentication bypass to code execution, and is intended for authorized testing and research purposes only.
This repository provides an operational exploit tool for CVE-2024-4358, implemented in Python (exploit.py). The tool is designed for both detection and mass exploitation of the vulnerability, supporting single or multiple targets via command-line arguments. It allows the user to specify a shell command to execute on the target (default: 'id'), and attempts to exploit a deserialization RCE by uploading a crafted report to the /api/reportserver/report endpoint. The tool retrieves and displays credentials and authentication tokens if successful, and can output results to a file. The code uses asynchronous requests for efficiency and supports proxying, threading, and verbose output. The README provides detailed usage instructions and sample output, confirming the tool's ability to execute arbitrary commands and extract sensitive information from vulnerable targets. No hardcoded IPs or credentials are present; all targets are user-supplied. The requirements.txt lists necessary Python dependencies for asynchronous and colored output.
This repository provides a mass exploitation tool for CVE-2024-4358, targeting a web application vulnerable to authentication bypass and deserialization attacks. The main script, 'exploit.py', is a Python 3 tool that automates the exploitation process across multiple targets, as specified in a user-provided file. The tool first attempts to bypass authentication by registering a new user via the '/Startup/Register' endpoint, then logs in to obtain an authentication token from '/Token'. It crafts a malicious serialized payload (in a .trdp file) containing a user-supplied OS command, uploads it to '/api/reportserver/report', and triggers deserialization via additional API endpoints. Successful exploitation results in arbitrary command execution on the target server, with credentials saved to 'credentials.txt'. The repository includes a README with usage instructions and a requirements.txt for dependencies. The exploit is operational, supports multi-threaded attacks, and is designed for mass exploitation scenarios.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication bypass in Progress Telerik Report Server's registration/startup flow that allows unauthenticated attackers to create an administrator account, enabling chaining with the deserialization flaw for pre-authenticated RCE.
A vulnerability in Progress Telerik Report Server, details unspecified, for which detection artifacts and exploit code exist.
A critical authentication bypass vulnerability in Progress Telerik Report Server for Windows IIS, allowing unauthenticated remote attackers to access restricted server functionality without valid credentials. Affects versions before 10.1.24.514.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.