CISA Known Exploited Vulnerability

CVE-2019-18935 Ransomware

Progress · Telerik UI for ASP.NET AJAX

Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Date added
BOD 22-01 due date
CWE CWE-502
Ransomware Known

CISA description

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

Required action

Apply updates per vendor instructions.