CVE-2017-11357
Act now ● On CISA KEV — actively exploited used in ransomware
Actively exploited — on the CISA KEV list.
CVSS base
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
77.7%
99.5th percentile
CISA KEV
Listed
Added 2023-01-26 · patch by 2023-02-16
Weakness / dates
CWE-434
Published 2017-08-23 · modified 2026-08-14
CVSS breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | N | Network |
| Attack Complexity | L | Low |
| Privileges Required | N | None |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | H | High |
| Integrity | H | High |
| Availability | H | High |
Timeline
- 2017-08-23 — Published (NVD)
- 2023-01-26 — Added to CISA KEV (actively exploited)
- 2023-02-16 — CISA patch-by deadline
- 2026-08-14 — Last modified (NVD)
Description
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
Affected
References
- http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/insecure-direct-object-reference
- exploit https://www.exploit-db.com/exploits/43874/
- http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/insecure-direct-object-reference
- exploit https://www.exploit-db.com/exploits/43874/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-11357