VulnerabilityAnalyzed
CVE-2017-11317
Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability
KEVCRITICAL 9.8EPSS 84.2%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 2 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 84.17% probability · 100th percentile
- CISA KEV
- Listed 11 April 2022 · due 2 May 2022
- Weakness
- CWE-326
- Affected
- telerik/ui for asp.net ajax
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-11317
References
- http://packetstormsecurity.com/files/159653/Telerik-UI-ASP.NET-AJAX-RadAsyncUpload-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/unrestricted-file-uploadMitigation, Vendor Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0006Third Party Advisory
- https://www.exploit-db.com/exploits/43874/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/159653/Telerik-UI-ASP.NET-AJAX-RadAsyncUpload-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/unrestricted-file-uploadMitigation, Vendor Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0006Third Party Advisory
- https://www.exploit-db.com/exploits/43874/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-11317US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.