Skip to content
COOEY

FAIL › dossier

User Interface (UI) for ASP.NET AJAX

PRODUCT

· dossier confidence 50%

Telerik's UI for ASP.NET AJAX has been exploited for remote code execution vulnerabilities, indicating potential weaknesses in their secure development practices. Remediation of these vulnerabilities and a review of their software development lifecycle are recommended.

PROFILE
CategorySoftware DevelopmentWhat they doTelerik develops UI components and tools for software developers. Their products are used to build web, mobile, and desktop applications.
SECURITY POSTURE

Telerik has a history of critical and high-severity remote code execution vulnerabilities in their UI for ASP.NET AJAX product. These vulnerabilities have allowed for arbitrary file uploads and code execution.

Notable failures
  • CVE-2017-11357 (RCE)
  • CVE-2017-11317 (RCE)
Patterns: Insecure direct object reference; Remote code execution
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-04-11 CVE-2017-11317 high Telerik UI for ASP.NET AJAX allowed remote attackers to upload arbitrary files and execute code due to an unrestricted file upload vulnerability.
2023-01-26 CVE-2017-11357 critical Telerik UI for ASP.NET AJAX suffered an insecure direct object reference flaw allowing file uploads and potential remote code execution.
Open questions: What is Telerik's current ownership? · What is Telerik's website?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-08 04:06:30.836380+00:00