Executive brief
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX uses weak RadAsyncUpload encryption, allowing remote attackers to perform arbitrary file uploads or execute arbitrary code via a deserialization flaw. The vulnerability stems from inadequate encryption strength in the file upload component.
Affected products
- Progress Telerik UI for ASP.NET AJAX (RadAsyncUpload) before R1 2017 and R2 before R2 2017 SP2
Timeline
- 2017-08-23: disclosed: NVD Published Date
- 2022-04-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog