Junglewise Threat Intelligence

CVE-2017-11317: Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability

CVE-2017-11317 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-04-11

Executive brief

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX uses weak RadAsyncUpload encryption, allowing remote attackers to perform arbitrary file uploads or execute arbitrary code via a deserialization flaw. The vulnerability stems from inadequate encryption strength in the file upload component.

Affected products

  • Progress Telerik UI for ASP.NET AJAX (RadAsyncUpload) before R1 2017 and R2 before R2 2017 SP2

Timeline

  • 2017-08-23: disclosed: NVD Published Date
  • 2022-04-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats