Telerik UI for ASP NET AJAX is a set of UI components widely used in web applications, reducing the time required to build web forms applications for any browser and device by half. Telerik UI for ASP NET AJAX is a complete ASP NET AJAX user interface development toolkit.
Telerik UI for ASP NET AJAX has an RCE vulnerability caused by deserialization, which allows attackers to execute code on the server side, write backdoors, gain server privileges, and ultimately control the entire web server.
", "Impact": "Telerik UI for ASP NET AJAX has an RCE vulnerability caused by deserialization, which allows attackers to execute code on the server side, write backdoors, gain server privileges, and ultimately control the entire web server.
", "Recommendation": "1. The manufacturer has released an upgrade patch to fix the vulnerability. The link to obtain the patch is: https://www.telerik.com/support/kb/aspnet-ajax/details/allows-javascriptserializer-deserialization
2. If not necessary, public network access to the system is prohibited.
3. Set access policies and whitelist access through security devices such as firewalls.
", "Product": "Telerik-UI", "VulType": [ "Code Execution" ], "Tags": [ "Code Execution" ], "Translation": { "CN": { "Name": "Telerik UI ASP.NET AJAX 反序列化 RCE 漏洞(CVE-2019-18935)", "Product": "Telerik-UI-for-ASP.NET", "Description": "Telerik UI for ASP.NET AJAX 是一套广泛用于 Web 应用程序的 UI 组件,将为任何浏览器和设备构建Web Forms应用程序的时间缩短一半。Telerik UI for ASP.NET AJAX是完整的 ASP.NET AJAX 用户界面开发工具集。
Telerik UI for ASP.NET AJAX 存在反序列化导致的 RCE 漏洞,攻击者可通过该漏洞在服务器端任意执行代码,写入后门,获取服务器权限,进而控制整个web服务器。
1、厂商已发布升级补丁以修复漏洞,补丁获取链接: https://www.telerik.com/support/kb/aspnet-ajax/details/allows-javascriptserializer-deserialization
2、如非必要,禁止公网访问该系统。
3、通过防火墙等安全设备设置访问策略,设置白名单访问。
", "Impact": "Telerik UI for ASP.NET AJAX 存在反序列化导致的 RCE 漏洞,攻击者可通过该漏洞在服务器端任意执行代码,写入后门,获取服务器权限,进而控制整个web服务器。
Telerik UI for ASP NET AJAX is a set of UI components widely used in web applications, reducing the time required to build web forms applications for any browser and device by half. Telerik UI for ASP NET AJAX is a complete ASP NET AJAX user interface development toolkit.
Telerik UI for ASP NET AJAX has an RCE vulnerability caused by deserialization, which allows attackers to execute code on the server side, write backdoors, gain server privileges, and ultimately control the entire web server.
", "Recommendation": "1. The manufacturer has released an upgrade patch to fix the vulnerability. The link to obtain the patch is: https://www.telerik.com/support/kb/aspnet-ajax/details/allows-javascriptserializer-deserialization
2. If not necessary, public network access to the system is prohibited.
3. Set access policies and whitelist access through security devices such as firewalls.
", "Impact": "Telerik UI for ASP NET AJAX has an RCE vulnerability caused by deserialization, which allows attackers to execute code on the server side, write backdoors, gain server privileges, and ultimately control the entire web server.