CVE-2019-18935
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to ...
Description
This CSAF advisory was extracted from unstructured data and may contain inaccuracies. If you notice any errors, please reach out to the designated contact at CISA CSAF: central@cisa.dhs.gov
In plain language
AI Act nowCVE-2019-18935 is a server bug in Telerik UI for ASP.NET AJAX that can let attackers run malicious code without needing a user login; if someone knows the special encryption keys, this is a serious risk—small businesses using this product should treat it as urgent.
Progress Telerik UI for ASP.NET AJAX (RadAsyncUpload) through 2019.3.1023 has a .NET deserialization issue that enables arbitrary server code execution over the network when an attacker possesses the specific encryption keys used by the feature.
What to do now
- Check whether you use “Telerik UI for ASP.NET AJAX” and whether your installed version is older than 2019.3.1023 in your web app/server.
- If you are using it, upgrade to the vendor-fixed version(s) listed in Telerik’s advisory for CVE-2019-18935 (follow your vendor’s upgrade guidance).
- If you can’t upgrade immediately, stop exposing the affected site/app features to the public internet and review for any signs of unauthorized access or suspicious uploads using RadAsyncUpload.
- Confirm the encryption-key-related condition is not met (no secrets have been leaked), and monitor server logs closely for repeated attempts targeting RadAsyncUpload.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Releaseden·The Hacker News· PoC Telerik UI for ASP.NET AJAX rce
- UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkiten·The Hacker News· Exploited UAT-10147 malware
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operationsen·Cisco Talos· Exploited Windows Server UAT-10147
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2019-18935 and every CVE in our database. Create a free account — no credit card required.
Create Free Account