US Government IIS Server Breached via Telerik Software Flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-18935 | Unauthenticated .NET Deserialization RCE in Progress Telerik UI for ASP.NET AJAX CVE-2019-18935 is a .NET deserialization flaw (CWE-502) in the RadAsyncUpload function of Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023. It is triggered when an attacker who knows the Telerik upload encryption keys — most commonly because the earlier flaws CVE-2017-11317 or CVE-2017-11357 exposed them, though keys can be obtained by other means — sends crafted serialized data to RadAsyncUpload, allowing remote code execution without authentication. Successful exploitation gives an attacker arbitrary code execution on the hosting IIS/ASP.NET web server, reflected in the critical 9.8 CVSS score. Any web application built with Telerik UI for ASP.NET AJAX at or below 2019.3.1023 is affected, unless 2019.3.1023 has the non-default hardening setting enabled (as of 2020.1.114 a default setting prevents the exploit). Exploitation is rampant in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, carries a 99.7% EPSS probability of exploitation, has multiple public exploits (Bishop Fox, RAU_crypto, noperator), and has been used by multiple threat groups — including ransomware and government-linked actors — to breach organizations including a U.S. federal agency. Do: Upgrade to Progress Telerik UI for ASP.NET AJAX 2020.1.114 or later, where a default setting prevents exploitation (or, if staying on 2019.3.1023, enable the non-default hardening setting); per CISA KEV, apply updates per vendor instructions. Because exploitation requires the encryption keys to be known, also patch the older CVE-2017-11317/CVE-2017-11357 key-disclosure flaws or rotate the Telerik upload encryption keys. Check internet-facing IIS/ASP.NET applications for exposed RadAsyncUpload handlers and indicators of compromise, given known ransomware and federal-agency breaches. | 9.8 | 100% | KEV ransomware PoC ×4 |
| largeTens of thousands of internet-exposed ASP.NET/IIS web applications using Telerik controls (order-of-magnitude estimate) |
Full article339 words · extracted from infosecurity-magazine.com · click to collapse
The US Cybersecurity and Infrastructure Security Agency (CISA) has disclosed information regarding a .NET deserialization vulnerability (CVE-2019-18935) in the Progress Telerik user interface (UI) for ASP.NET AJAX.
CISA described the findings in an advisory on Wednesday, saying multiple cyber-threat actors were able to exploit the flaw, which also affected the Microsoft Internet Information Services (IIS) web server of a federal civilian executive branch (FCEB) agency between November 2022 and January 2023.
If exploited successfully, the vulnerability allows remote code execution (RCE). Because of this, the flaw has been rated as critical and assigned a CVSS v3.1 score of 9.8.
Read more on the CVSS system here: A Case Against CVSS
“Though the agency’s vulnerability scanner had the appropriate plugin for CVE-2019-18935, it failed to detect the vulnerability due to the Telerik UI software being installed in a file path it does not typically scan,” reads the CISA advisory. “This may be the case for many software installations, as file paths widely vary depending on the organization and installation method.”
Commenting on the news, Dror Liwer, co-founder of cybersecurity company Coro, said vulnerabilities like this are a “low-hanging fruit” for attackers.
“They represent an easy, well-documented entry point that does not require social engineering, strong technical skills or active monitoring,” Liwer explained.
According to the executive, keeping up with known vulnerabilities across all assets can be daunting, but organizations must pay more attention to updates.
“There is no easy fix. Vulnerability management must be an integral part of any cybersecurity program, as tedious and laborious as it may be,” Liwer added.
As far as CVE-2019-18935 is concerned, CISA said entities using Progress Telerik software should implement a patch management solution to ensure compliance with the latest security patches.
They should also validate the output from patch management and vulnerability scanning against running services to check for any discrepancies, and limit service accounts to the minimum permissions necessary.
The CISA advisory comes weeks after SentinelOne disclosed information related to new malware loaders based on the .NET development platform.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/us-server-breached-via-telerik/