Junglewise Threat Intelligence

CVE-2019-18935: Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

CVE-2019-18935 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: Progress.

Executive brief

Progress Telerik UI for ASP.NET AJAX contains a .NET deserialization vulnerability in the RadAsyncUpload function. When encryption keys are known, an unauthenticated attacker can achieve remote code execution on the server.

Affected products

  • Telerik UI for ASP.NET AJAX through 2019.3.1023

Timeline

  • 2019-12-17: disclosed: Initial public disclosure via Packet Storm
  • 2020-01-14: patched: Fixed in version 2020.1.114 where a default setting prevents the exploit
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog