CVE-2019-18935
Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 99.74% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
- Weakness
- CWE-502
- Affected
- telerik/ui for asp.net ajax
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-18935
References
- http://packetstormsecurity.com/files/155720/Telerik-UI-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/159653/Telerik-UI-ASP.NET-AJAX-RadAsyncUpload-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- https://codewhitesec.blogspot.com/2019/02/telerik-revisited.htmlNot Applicable
- https://github.com/bao7uo/RAU_cryptoExploit, Third Party Advisory
- https://github.com/noperator/CVE-2019-18935Exploit, Third Party Advisory
- https://know.bishopfox.com/research/cve-2019-18935-remote-code-execution-in-telerik-uiExploit, Third Party Advisory
- https://www.bleepingcomputer.com/news/security/us-federal-agency-hacked-using-old-telerik-bug-to-steal-data/Press/Media Coverage
- https://www.telerik.com/support/kb/aspnet-ajax/details/allows-javascriptserializer-deserializationPatch, Vendor Advisory
- https://www.telerik.com/support/whats-new/aspnet-ajax/release-history/ui-for-asp-net-ajax-r1-2020-%28version-2020-1-114%29Release Notes
- https://www.telerik.com/support/whats-new/release-historyRelease Notes, Vendor Advisory
- http://packetstormsecurity.com/files/155720/Telerik-UI-Remote-Code-Execution.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/159653/Telerik-UI-ASP.NET-AJAX-RadAsyncUpload-Deserialization.htmlExploit, Third Party Advisory, VDB Entry
- https://codewhitesec.blogspot.com/2019/02/telerik-revisited.htmlNot Applicable
- https://github.com/bao7uo/RAU_cryptoExploit, Third Party Advisory
- https://github.com/noperator/CVE-2019-18935Exploit, Third Party Advisory
- https://know.bishopfox.com/research/cve-2019-18935-remote-code-execution-in-telerik-uiExploit, Third Party Advisory
- https://www.bleepingcomputer.com/news/security/us-federal-agency-hacked-using-old-telerik-bug-to-steal-data/Press/Media Coverage
- https://www.telerik.com/support/kb/aspnet-ajax/details/allows-javascriptserializer-deserializationPatch, Vendor Advisory
- https://www.telerik.com/support/whats-new/aspnet-ajax/release-history/ui-for-asp-net-ajax-r1-2020-%28version-2020-1-114%29Release Notes
- https://www.telerik.com/support/whats-new/release-historyRelease Notes, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-18935US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.