ZeroHour

CVE-2017-11357

KEV ransomware PoC large

Unauthenticated Arbitrary File Upload/RCE in Progress Telerik UI for ASP.NET AJAX

CISA: Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability

CVSS 3.1
9.8 critical
EPSS
78%p100
Published
()
KEV added
AI analysis

CVE-2017-11357 is an insecure direct object reference in the RadAsyncUpload control of Progress Telerik UI for ASP.NET AJAX: user input is not properly restricted, so an unauthenticated remote attacker can upload arbitrary files to attacker-chosen locations. Because an attacker can drop a malicious file such as an ASPX web shell and then trigger it, the flaw leads to arbitrary code execution on the affected web server (CVSS 3.1 9.8; CWE-434). Any ASP.NET web application running Telerik UI for ASP.NET AJAX before R2 2017 SP2 that exposes the upload handler to untrusted users is affected. A public proof of concept is available (Exploit-DB 43874), and exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-01-26 with known ransomware use, has an EPSS of 77.7% (100th percentile), and recent news reports tied Telerik exploitation to the breach of a U.S. federal agency, in line with NSA/ASD warnings about web shell deployments.

What to do: Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP2 or later per vendor instructions; if the control is embedded in a third-party application, obtain updated builds from that application's vendor. Audit web roots and upload directories for unexpected .aspx/.asp files and web shells, review IIS logs for suspicious requests to the Telerik upload handler, and restrict internet access to the RadAsyncUpload handler if immediate patching is not possible. Given confirmed ransomware use, prioritize internet-facing systems and treat any evidence of file uploads through the handler as potential compromise.

Affected
Progress Telerik UI for ASP.NET AJAXall versions before R2 2017 SP2
Estimated exposure
largetens of thousands of internet-exposed ASP.NET applications using Telerik UI (likely more, since the component ships embedded in internal and third-party apps) — Telerik UI for ASP.NET AJAX is one of the most widely licensed commercial .NET UI component suites and is frequently bundled into third-party ASP.NET web applications; public internet scans have repeatedly shown on the order of tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

CISA Known Exploited Vulnerability
Affected
Telerik User Interface (UI) for ASP.NET AJAX
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
progress
Products
telerik ui for asp.net ajax
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news