CVE-2017-11317
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-04-11Remediation due 2022-05-02
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
9.8
CVSS
84.2%
EPSS (exploit prob.)
100th
EPSS percentile
2017-08-23
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-326
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| telerik | ui_for_asp.net_ajax | <= 2016.3.1027 |
| telerik | ui_for_asp.net_ajax | 2017.2.503 |
| telerik | ui_for_asp.net_ajax | 2017.2.621 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/159653/Telerik-UI-ASP.NET-AJAX-RadAsyncUpload-Deserialization.html
- http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/unrestricted-file-upload
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0006
- https://www.exploit-db.com/exploits/43874/
- http://packetstormsecurity.com/files/159653/Telerik-UI-ASP.NET-AJAX-RadAsyncUpload-Deserialization.html
- http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/unrestricted-file-upload
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0006
- https://www.exploit-db.com/exploits/43874/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-11317
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-11317