Executive brief
Progress Telerik UI for ASP.NET AJAX contains a .NET deserialization vulnerability in the RadAsyncUpload function. When encryption keys are known, an unauthenticated attacker can achieve remote code execution on the server.
Affected products
- Telerik UI for ASP.NET AJAX through 2019.3.1023
Timeline
- 2019-12-17: disclosed: Initial public disclosure via Packet Storm
- 2020-01-14: patched: Fixed in version 2020.1.114 where a default setting prevents the exploit
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog