Executive brief
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX and Sitefinity contains a cryptographic weakness that fails to properly protect encryption keys. Remote attackers can exploit this to leak the MachineKey, perform arbitrary file uploads/downloads, execute XSS attacks, or compromise the ASP.NET ViewState.
Affected products
- Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 (2017.2.621)
- Progress Telerik Sitefinity before 10.0.6412.0
Timeline
- 2017-07-03: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2018-01-24: other: Exploit-DB entry published (approximate based on reference date)