Junglewise Threat Intelligence

CVE-2017-9248: Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

CVE-2017-9248 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Progress Sitefinity, Progress Telerik UI for ASP.NET AJAX. Vendors: Progress.

Executive brief

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX and Sitefinity contains a cryptographic weakness that fails to properly protect encryption keys. Remote attackers can exploit this to leak the MachineKey, perform arbitrary file uploads/downloads, execute XSS attacks, or compromise the ASP.NET ViewState.

Affected products

  • Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 (2017.2.621)
  • Progress Telerik Sitefinity before 10.0.6412.0

Timeline

  • 2017-07-03: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2018-01-24: other: Exploit-DB entry published (approximate based on reference date)

Related threats