CVE-2017-11357
Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 16 February 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 77.68% probability · 100th percentile
- CISA KEV
- Listed 26 January 2023 · due 16 February 2023 · used in ransomware campaigns
- Weakness
- CWE-434
- Affected
- progress/telerik ui for asp.net ajax
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://docs.telerik.com/devtools/aspnet-ajax/knowledge-base/asyncupload-insecure-direct-object-reference; https://nvd.nist.gov/vuln/detail/CVE-2017-11357
References
- http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/insecure-direct-object-referenceMitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/43874/Exploit, Third Party Advisory, VDB Entry
- http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/insecure-direct-object-referenceMitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/43874/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-11357US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.