CVE-2017-11357

Confirmed PUBLISHED

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to...

Vendor: Progress Product: Telerik UI for ASP.NET AJAX
Exploited in the wild Used in malware

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 75.7%

At a Glance

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

nessus_scanner cisa dotnet malware ransomware
CVE Published
Aug 23, 2017
Exploitation Reported
Jan 26, 2023
CVSS
9.8 Critical
EPSS
75.7%
Remote Low complexity No user interaction Unauthenticated

CVE References