Back

CRITICAL KEV Used in ransomware campaigns

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function

Published Dec 11, 2019 ·Due May 3, 2022

Description

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)

Affected products

Remediation

No remediation recorded yet.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 11, 2019
Updated Oct 21, 2025
Reserved Nov 13, 2019
CISA Vulnrichment
Updated Feb 4, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner mitre
Published Dec 11, 2019
Updated Oct 21, 2025
Exploited since Nov 3, 2021
EUVD-2019-8608