ZeroHour

CVE-2017-11317

KEV PoC ×2large

Unrestricted File Upload / RCE in Progress Telerik UI for ASP.NET AJAX

CISA: Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability

CVSS 3.1
9.8 critical
EPSS
84%p100
Published
()
KEV added
AI analysis

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and in R2 releases before R2 2017 SP2 uses weak encryption for the RadAsyncUpload component, allowing unauthenticated remote attackers to forge upload parameters, upload arbitrary files to the web server, and ultimately execute arbitrary code. The flaw is triggered simply by sending crafted requests to the vulnerable upload handler over the network, with no authentication or user interaction required. Successful exploitation gives an attacker arbitrary file upload and remote code execution in the context of the ASP.NET application, which is typically hosted on IIS web servers. Any site or application built with Telerik UI for ASP.NET AJAX is affected, and the weakness is confirmed exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-11, and related reporting describes multiple hacking groups — including IIS/ASP.NET-focused APT actors — breaching a U.S. federal agency through it.

What to do: Upgrade Telerik UI for ASP.NET AJAX to R1 2017 or R2 2017 SP2 (or later) per vendor instructions, and verify the deployed Telerik.Web.UI.dll version in each application's bin folder. Given active in-the-wild exploitation of IIS/ASP.NET applications, review affected web servers for unauthorized uploads and web shells and rotate ASP.NET machine keys used with RadAsyncUpload.

Affected
Telerik (Progress) UI for ASP.NET AJAX (Telerik.Web.UI / RadAsyncUpload)before R1 2017; R2 releases before R2 2017 SP2
Estimated exposure
large≈tens of thousands of internet-exposed ASP.NET/IIS applications; the total installed base (including internal apps) is plausibly far larger — Public internet scans of Telerik UI for ASP.NET AJAX signatures have consistently surfaced tens of thousands of exposed hosts, and the component ships inside many commercial and custom ASP.NET web applications, making the broader installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Telerik User Interface (UI) for ASP.NET AJAX
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
telerik
Products
ui for asp.net ajax
Weakness
CWE-326
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news