CVE-2019-18935 - Progress Telerik UI for ASP.NET AJAX
AI Vulnerability ContextProgress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a n...
Overview
A source-backed snapshot of this vulnerability.
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2019-18935
- Vendor/project
- Progress
- Product
- Telerik UI for ASP.NET AJAX
- Vulnerability name
- Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
- Date added
- 2021-11-03
- Due date
- 2022-05-03
- Known ransomware campaign use
- Known
- CVSS v3
- 9.8
Exploit context
What the vulnerability is about.
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
