CVE-2017-9248
Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 75.10% probability · 99th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022
- Weakness
- CWE-522
- Affected
- progress/sitefinity · telerik/ui for asp.net ajax
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2017-9248
References
- http://www.securityfocus.com/bid/99965Broken Link, Third Party Advisory, VDB Entry
- http://www.telerik.com/blogs/security-alert-for-telerik-ui-for-asp.net-ajax-and-progress-sitefinityVendor Advisory
- http://www.telerik.com/support/kb/aspnet-ajax/details/cryptographic-weaknessMitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/43873/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/99965Broken Link, Third Party Advisory, VDB Entry
- http://www.telerik.com/blogs/security-alert-for-telerik-ui-for-asp.net-ajax-and-progress-sitefinityVendor Advisory
- http://www.telerik.com/support/kb/aspnet-ajax/details/cryptographic-weaknessMitigation, Vendor Advisory
- https://www.exploit-db.com/exploits/43873/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9248US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.