EXPOSURES › CVE-2017-11357
CVE-2017-11357
CRITICAL ⌖ ON CISA KEV · EXPLOITEDTelerik UI for ASP.NET AJAX suffered an insecure direct object reference flaw allowing file uploads and potential remote code execution.
The vulnerability in RadAsyncUpload permitted authenticated users to upload files to restricted locations, potentially leading to remote code execution. DIB organizations must ensure all UI components are patched, as unpatched flaws in widely used libraries can become ransomware entry points. Organizations should verify their software supply chain for known KEV vulnerabilities.
Shame score — A known vulnerability in a widely deployed UI component was left unpatched, enabling ransomware-linked attacks and remote code execution.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.