EXPOSURES › CVE-2019-18935
CVE-2019-18935
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA deserialization vulnerability in Progress Telerik UI for ASP.NET AJAX allowed for remote code execution, and is actively being exploited in ransomware attacks.
CVE-2019-18935, a deserialization flaw in Telerik UI for ASP.NET AJAX, enables code execution via the RadAsyncUpload component, potentially allowing attackers to compromise servers. DIB organizations using this component are at risk of ransomware and must immediately patch or mitigate the vulnerability to maintain CMMC compliance. Failure to address this actively exploited vulnerability demonstrates negligence.
Shame score — The vulnerability's active exploitation in ransomware campaigns and the potential for server compromise highlight a significant and avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.
"Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process."