PT-2019-4636 · Progress · Telerik Ui For Asp.Net Ajax

Bao7Uo

+1

·

Publicado

2019-12-11

·

Atualizado

2026-04-09

·

CVE-2019-18935

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Progress Telerik UI for ASP.NET AJAX versions prior to 2020.1.114
Description The issue concerns the deserialization of untrusted data, allowing for remote code execution. This has been exploited by multiple threat actors, including a nation-state group, to breach a U.S. federal agency's web server. The estimated number of potentially affected devices worldwide is not specified. Technical details include the exploitation of insecure deserialization in Telerik UI. API endpoints and specific variables are not explicitly mentioned.
Recommendations As a temporary workaround, consider disabling the deserialization of untrusted data in Progress Telerik UI for ASP.NET AJAX until a patch is available. Restrict access to vulnerable components to minimize the risk of exploitation. For versions prior to 2020.1.114, update to version 2020.1.114 or later to resolve the issue. At the moment, there is no information about additional mitigation measures.

Exploit

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2020-00797
CVE-2019-18935
ZDI-25-468

Produtos afetados

Telerik Ui For Asp.Net Ajax