Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HTelerik Ui For Asp.net Ajax
APPTelerik2011.1.315 – 2020.1.114
CISA KEV — detailsi
- Vendori
- Progress ↗
- Producti
- Telerik UI for ASP.NET AJAX
- Added to KEVi
- November 3, 2021
- Remediation deadline (US Federal)i
- May 3, 2022(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply updates per vendor instructions.
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
Related vulnerabilities
Telerik UI for ASP.NET AJAX — słabe szyfrowanie RadAsyncUpload umożliwia RCE
Słaba ochrona kryptograficzna w Telerik UI for ASP.NET AJAX i Sitefinity
Telerik Report Server – pominięcie uwierzytelniania (authentication bypass)
Path Traversal w RadChart (Telerik UI for ASP.NET AJAX) — odczyt i usuwanie plików graficznych
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible th...