PT-2019-4636 · Progress · Telerik Ui For Asp.Net Ajax

Bao7Uo

+1

·

Published

2019-12-11

·

Updated

2026-04-09

·

CVE-2019-18935

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Progress Telerik UI for ASP.NET AJAX versions prior to 2020.1.114
Description The issue concerns the deserialization of untrusted data, allowing for remote code execution. This has been exploited by multiple threat actors, including a nation-state group, to breach a U.S. federal agency's web server. The estimated number of potentially affected devices worldwide is not specified. Technical details include the exploitation of insecure deserialization in Telerik UI. API endpoints and specific variables are not explicitly mentioned.
Recommendations As a temporary workaround, consider disabling the deserialization of untrusted data in Progress Telerik UI for ASP.NET AJAX until a patch is available. Restrict access to vulnerable components to minimize the risk of exploitation. For versions prior to 2020.1.114, update to version 2020.1.114 or later to resolve the issue. At the moment, there is no information about additional mitigation measures.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00797
CVE-2019-18935
ZDI-25-468

Affected Products

Telerik Ui For Asp.Net Ajax