Skip to content
COOEY

EXPOSURES › CVE-2017-11317

CVE-2017-11317

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2017-11317 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildunpatched

Telerik UI for ASP.NET AJAX allowed remote attackers to upload arbitrary files and execute code due to an unrestricted file upload vulnerability.

The Telerik UI for ASP.NET AJAX product contained an unrestricted file upload flaw enabling remote code execution, a critical failure for DIB vendors relying on third-party UI components. This exposes systems to malware, ransomware, and data theft, violating CMMC/NIST 800-171 requirements for secure supply chain and patch management. Organizations must audit third-party UI libraries and enforce strict file upload controls to prevent similar exploits.

Shame score — A known, actively exploited vulnerability in a widely used UI component that allowed remote code execution and arbitrary file uploads, demonstrating severe negligence in secure development and patching.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.