EXPOSURES › CVE-2021-23758
CVE-2021-23758
HIGH ⌖ ON CISA KEV · EXPLOITEDAjax.NET Professional suffered a deserialization vulnerability allowing remote code execution via arbitrary .NET classes.
The Ajax.NET Professional product contained a deserialization of untrusted data vulnerability that enabled remote code execution. DIB organizations must ensure they are not using end-of-life or end-of-service components, as this failure highlights the risk of relying on unsupported software. Organizations should immediately audit their supply chain for similar unpatched or EoL components and transition to supported versions.
Shame score — The vulnerability was actively exploited in the wild (KEV list) and allowed remote code execution, indicating a severe, avoidable failure in maintaining secure, supported software.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.