← All CVEs

CVE-2017-11317

critical · 9.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-04-11Remediation due 2022-05-02

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

9.8
CVSS
84.2%
EPSS (exploit prob.)
100th
EPSS percentile
2017-08-23
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-326

Affected products

VendorProductAffected versions
telerikui_for_asp.net_ajax<= 2016.3.1027
telerikui_for_asp.net_ajax2017.2.503
telerikui_for_asp.net_ajax2017.2.621

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2017-11317