CVE-2017-11357
KEV ransomware PoC largeUnauthenticated Arbitrary File Upload/RCE in Progress Telerik UI for ASP.NET AJAX
CISA: Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
CVE-2017-11357 is an insecure direct object reference in the RadAsyncUpload control of Progress Telerik UI for ASP.NET AJAX: user input is not properly restricted, so an unauthenticated remote attacker can upload arbitrary files to attacker-chosen locations. Because an attacker can drop a malicious file such as an ASPX web shell and then trigger it, the flaw leads to arbitrary code execution on the affected web server (CVSS 3.1 9.8; CWE-434). Any ASP.NET web application running Telerik UI for ASP.NET AJAX before R2 2017 SP2 that exposes the upload handler to untrusted users is affected. A public proof of concept is available (Exploit-DB 43874), and exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-01-26 with known ransomware use, has an EPSS of 77.7% (100th percentile), and recent news reports tied Telerik exploitation to the breach of a U.S. federal agency, in line with NSA/ASD warnings about web shell deployments.
What to do: Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP2 or later per vendor instructions; if the control is embedded in a third-party application, obtain updated builds from that application's vendor. Audit web roots and upload directories for unexpected .aspx/.asp files and web shells, review IIS logs for suspicious requests to the Telerik upload handler, and restrict internet access to the RadAsyncUpload handler if immediate patching is not possible. Given confirmed ransomware use, prioritize internet-facing systems and treat any evidence of file uploads through the handler as potential compromise.
| Progress Telerik UI for ASP.NET AJAX | all versions before R2 2017 SP2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
- Affected
- Telerik User Interface (UI) for ASP.NET AJAX
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- progress
- Products
- telerik ui for asp.net ajax
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H