CVE-2019-18935
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- November 13, 2019
- Published Date
- December 11, 2019
- Last Updated
- February 04, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
CVSS Scores
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-03 00:00:00 UTC |
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/telerik_rau_deserialization.rb | 2025-04-29 11:01:39 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
telerik_rau_deserialization
Type: metasploit • Created: Unknown
dust-life/CVE-2019-18935-memShell
Type: github • Created: 2023-12-25 06:45:11 UTC • Stars: 6
random-robbie/CVE-2019-18935
Type: github • Created: 2020-09-30 10:00:16 UTC • Stars: 5
murataydemir/CVE-2019-18935
Type: github • Created: 2020-08-19 17:11:02 UTC • Stars: 15
ThanHuuTuan/Telerik_CVE-2019-18935
Type: github • Created: 2020-05-25 08:37:51 UTC • Stars: 12
noperator/CVE-2019-18935
Type: github • Created: 2019-12-12 07:58:11 UTC • Stars: 351