CVE-2017-9248
critical · 9.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2022-05-03
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
9.8
CVSS
75.1%
EPSS (exploit prob.)
99th
EPSS percentile
2017-07-03
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-522
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| progress | sitefinity | < 10.0.6412.0 |
| telerik | ui_for_asp.net_ajax | <= 2017.2.503 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/99965
- http://www.telerik.com/blogs/security-alert-for-telerik-ui-for-asp.net-ajax-and-progress-sitefinity
- http://www.telerik.com/support/kb/aspnet-ajax/details/cryptographic-weakness
- https://www.exploit-db.com/exploits/43873/
- http://www.securityfocus.com/bid/99965
- http://www.telerik.com/blogs/security-alert-for-telerik-ui-for-asp.net-ajax-and-progress-sitefinity
- http://www.telerik.com/support/kb/aspnet-ajax/details/cryptographic-weakness
- https://www.exploit-db.com/exploits/43873/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9248
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-9248