PT-2019-4636 · Progress · Telerik Ui For Asp.Net Ajax
Bao7Uo
+1
·
Published
2019-12-11
·
Updated
2026-04-09
·
CVE-2019-18935
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Progress Telerik UI for ASP.NET AJAX versions prior to 2020.1.114
Description
The issue concerns the deserialization of untrusted data, allowing for remote code execution. This has been exploited by multiple threat actors, including a nation-state group, to breach a U.S. federal agency's web server. The estimated number of potentially affected devices worldwide is not specified. Technical details include the exploitation of insecure deserialization in Telerik UI. API endpoints and specific variables are not explicitly mentioned.
Recommendations
As a temporary workaround, consider disabling the deserialization of untrusted data in Progress Telerik UI for ASP.NET AJAX until a patch is available. Restrict access to vulnerable components to minimize the risk of exploitation. For versions prior to 2020.1.114, update to version 2020.1.114 or later to resolve the issue. At the moment, there is no information about additional mitigation measures.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Telerik Ui For Asp.Net Ajax