CVE-2025-3600
largeUnsafe Reflection DoS in Progress Telerik UI for ASP.NET AJAX (CVE-2025-3600)
CVE-2025-3600 is an unsafe reflection vulnerability (CWE-470) in Progress Telerik UI for ASP.NET AJAX, present in all builds from 2011.2.712 through 2025.1.218, in which attacker-controlled input used in a reflection operation can cause an unhandled exception. When triggered, the exception crashes the hosting process (typically the application pool serving the web application), resulting in denial of service; the CVSS vector (AV:N/AC:L/PR:N/UI:N, availability-only impact) confirms there is no confidentiality or integrity impact. Because exploitation requires no privileges or user interaction over the network, any web application built with the affected versions and exposing Telerik components or handlers to unauthenticated traffic is at risk. No public proof-of-concept or CISA KEV listing is currently known, but the 24.1% EPSS score (98th percentile) indicates a significantly elevated probability of exploitation within the next 30 days. The roughly 14-year affected version span means the flaw is likely present in a large, long-lived installed base of .NET web applications.
What to do: Upgrade Telerik UI for ASP.NET AJAX to a release newer than 2025.1.218 (confirm the exact fixed build in Progress's official security advisory). In the interim, inventory which web applications bundle Telerik UI for ASP.NET AJAX and restrict unauthenticated access to its handlers/endpoints, and ensure application-pool recovery or load-balanced redundancy is in place to limit denial-of-service impact. Monitor EPSS and the CISA KEV catalog, as the elevated 98th-percentile EPSS suggests exploitation activity may emerge soon.
| Progress Telerik UI for ASP.NET AJAX | 2011.2.712 through 2025.1.218 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.
- Vendors
- progress
- Products
- telerik ui for asp.net ajax
- Weakness
- CWE-470
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H