CVE-2019-18935 — Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
CVE-2019-18935: Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Progress |
| Product | Telerik UI for ASP.NET AJAX |
| Date added | 2021-11-03 |
| Due date | 2022-05-03 |
| Ransomware campaign use | Known |
Description
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2019-18935
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-18935
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog