Umbra Wiki cve cve/CVE-2019-18935
Back to wiki

CVE-2019-18935 — Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

provenance: imported · CVE: CVE-2019-18935 · CWE: CWE-502

CVE-2019-18935: Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Progress
Product Telerik UI for ASP.NET AJAX
Date added 2021-11-03
Due date 2022-05-03
Ransomware campaign use Known

Description

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2019-18935

Weakness behind it

CISA records this vulnerability as an instance of CWE-502. From there the chain continues into CAPEC attack patterns and ATT&CK techniques, all inside this corpus.

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-18935
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

See all 1,745 pages under Vulnerabilities (CVE) →