CVE-2019-18935
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
15Exploited in Wild
YesDecision
Descriptions
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
Progress Telerik UI para ASP.NET AJAX hasta 2019.3.1023 contiene una vulnerabilidad de deserialización de .NET en la función RadAsyncUpload. Esto es explotable cuando las claves de cifrado se conocen debido a la presencia de CVE-2017-11317 o CVE-2017-11357, u otros medios. La explotación puede resultar en la ejecución remota de código. (A partir de 2020.1.114, una configuración predeterminada evita la explotación. En 2019.3.1023, pero no en versiones anteriores, una configuración no predeterminada puede evitar la explotación).
The Telerik UI for ASP.NET AJAX insecurely deserializes JSON objects in a manner that results in arbitrary remote code execution on the software's underlying host.
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2019-11-13 CVE Reserved
- 2019-12-11 CVE Published
- 2019-12-18 First Exploit
- 2021-11-03 Exploited in Wild
- 2022-05-03 KEV Due Date
- 2025-01-08 EPSS Updated
- 2025-02-04 CVE Updated
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (24)
URL | Date | SRC |
---|---|---|
https://www.telerik.com/support/kb/aspnet-ajax/details/allows-javascriptserializer-deserialization | 2019-12-09 |
URL | Date | SRC |
---|---|---|
https://www.telerik.com/support/whats-new/release-history | 2024-07-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Telerik Search vendor "Telerik" | Ui For Asp.net Ajax Search vendor "Telerik" for product "Ui For Asp.net Ajax" | >= 2011.1.315 <= 2020.1.114 Search vendor "Telerik" for product "Ui For Asp.net Ajax" and version " >= 2011.1.315 <= 2020.1.114" | - |
Affected
|