ZeroHour

CVE-2017-9248

KEV PoC large

Cryptographic key leak (CWE-522) in Progress Telerik UI for ASP.NET AJAX & Sitefinity

CISA: Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

CVSS 3.1
9.8 critical
EPSS
75%p99
Published
()
KEV added
AI analysis

Progress Telerik UI for ASP.NET AJAX (Telerik.Web.UI.dll) before R2 2017 SP1 and Progress Sitefinity before 10.0.6412.0 fail to adequately protect the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey (CWE-522, insufficient key/credential protection). A remote, unauthenticated attacker can send crafted requests to the component's encrypted dialog-parameter handler to recover the dialog encryption key and then leak the MachineKey, and a public proof-of-concept exists (Exploit-DB 43873). With the MachineKey in hand, the attacker can forge or decrypt ASP.NET ViewState, upload or download arbitrary files, and inject XSS, which on IIS servers commonly chains to remote code execution via malicious ViewState. Any website or application embedding the vulnerable Telerik UI assembly, including older Sitefinity CMS releases, is affected. The flaw is confirmed exploited in the wild: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 75.1% EPSS score (99th percentile), and its use in ransomware campaigns is unknown.

What to do: Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP1 or later and Sitefinity to 10.0.6412.0 or later per vendor instructions, as required by CISA's KEV listing. After patching, rotate the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey, because keys leaked before patching remain usable to forge ViewState. Review IIS logs for requests to Telerik dialog handler endpoints and for unexpected file uploads, downloads, or ViewState-related anomalies.

Affected
Progress (Telerik) UI for ASP.NET AJAX (Telerik.Web.UI.dll)all versions before R2 2017 SP1
Progress (Telerik) Sitefinityall versions before 10.0.6412.0
Estimated exposure
largetens of thousands of internet-exposed vulnerable installations (estimate) — Estimated from deployment patterns: the Telerik UI for ASP.NET AJAX assembly is embedded in a very large installed base of ASP.NET/IIS web applications and Sitefinity CMS sites, and public internet-wide scans of Telerik dialog handler…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.

CISA Known Exploited Vulnerability
Affected
Progress ASP.NET AJAX and Sitefinity
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
progresstelerik
Products
sitefinity, ui for asp.net ajax
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news