Loading HuntDB...

Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Added Nov. 3, 2021 Due May 3, 2022 CVE-2019-18935
Overdue Progress / Telerik UI for ASP.NET AJAX Known Ransomware Use CWE-502

Description

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

Required Action

Apply updates per vendor instructions.

References

Additional Information

Catalog Version
2025.01.24
Catalog Released
Jan. 24, 2025
Days Until Due
0 days
Last Updated
8 months ago