ZeroHour

CVE-2025-3600

large

Unsafe Reflection DoS in Progress Telerik UI for ASP.NET AJAX (CVE-2025-3600)

CVSS 3.1
7.5 high
EPSS
24%p98
Published
()
Modified
AI analysis

CVE-2025-3600 is an unsafe reflection vulnerability (CWE-470) in Progress Telerik UI for ASP.NET AJAX, present in all builds from 2011.2.712 through 2025.1.218, in which attacker-controlled input used in a reflection operation can cause an unhandled exception. When triggered, the exception crashes the hosting process (typically the application pool serving the web application), resulting in denial of service; the CVSS vector (AV:N/AC:L/PR:N/UI:N, availability-only impact) confirms there is no confidentiality or integrity impact. Because exploitation requires no privileges or user interaction over the network, any web application built with the affected versions and exposing Telerik components or handlers to unauthenticated traffic is at risk. No public proof-of-concept or CISA KEV listing is currently known, but the 24.1% EPSS score (98th percentile) indicates a significantly elevated probability of exploitation within the next 30 days. The roughly 14-year affected version span means the flaw is likely present in a large, long-lived installed base of .NET web applications.

What to do: Upgrade Telerik UI for ASP.NET AJAX to a release newer than 2025.1.218 (confirm the exact fixed build in Progress's official security advisory). In the interim, inventory which web applications bundle Telerik UI for ASP.NET AJAX and restrict unauthenticated access to its handlers/endpoints, and ensure application-pool recovery or load-balanced redundancy is in place to limit denial-of-service impact. Monitor EPSS and the CISA KEV catalog, as the elevated 98th-percentile EPSS suggests exploitation activity may emerge soon.

Affected
Progress Telerik UI for ASP.NET AJAX2011.2.712 through 2025.1.218 (inclusive)
Estimated exposure
largelikely hundreds of thousands of application deployments, with tens of thousands of internet-exposed instances — Telerik UI for ASP.NET AJAX is a mainstream .NET UI control suite embedded in a very large population of web applications spanning over a decade of releases, and prior public internet-wide scans of Telerik-exposed endpoints have found tens…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.

Vendors
progress
Products
telerik ui for asp.net ajax
Weakness
CWE-470
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news