CRITICAL🚩 CISA KEV⚡ EXPLOIT🇵🇱 Wersja polska

CVE-2017-11357

CVSS 9.8v3.1pub. 2017-08-23upd. 2026-08-14

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Progress Telerik Ui For Asp.net Ajax

    APP
    Progress
    < 2020.1.114

CISA KEV — detailsi

Vendori
Telerik
Producti
User Interface (UI) for ASP.NET AJAX
Added to KEVi
January 26, 2023
Remediation deadline (US Federal)i
February 16, 2023(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply updates per vendor instructions.

CISA descriptioni

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 16 lutego 2023
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2021-28141CRITICAL9.8PL ✓same product

Nieautoryzowany dostęp do zasobów w Progress Telerik UI for ASP.NET AJAX

CVE-2019-19790CRITICAL9.8PL ✓same product

Path Traversal w RadChart (Telerik UI for ASP.NET AJAX) — odczyt i usuwanie plików graficznych

CVE-2026-13182HIGH7.5PL ✓same product

Padding oracle w RadAsyncUpload – ujawnienie metadanych w Telerik UI for AJAX

CVE-2026-13181HIGH8.1PL ✓same product

RCE w Progress Telerik UI for AJAX — fałszywe metadane uploadu

CVE-2026-13183HIGH7.5PL ✓same product

Timing oracle w RadAsyncUpload (Telerik UI for AJAX) — wyciek metadanych