Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
Overdue
Progress / Telerik UI for ASP.NET AJAX
Known Ransomware Use
CWE-502
Description
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
Required Action
Apply updates per vendor instructions.
Additional Information
- Catalog Version
- 2025.01.24
- Catalog Released
- Jan. 24, 2025
- Days Until Due
- 0 days
- Last Updated
- 8 months ago