Umbra Wiki cve cve/CVE-2019-18935
Back to wiki

CVE-2019-18935 — Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

provenance: imported · CVE: CVE-2019-18935

CVE-2019-18935: Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Progress
Product Telerik UI for ASP.NET AJAX
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Known

Description

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2019-18935

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-18935
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog