← Vulnerability feed

Vulnerability record · CVE-2017-11357 · published 23 August 2017

CVE-2017-11357: Telerik UI for ASP.NET AJAX RadAsyncUpload unrestricted file upload

Progress · Telerik Ui For Asp.Net Ajax

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 fails to properly restrict user input to the RadAsyncUpload control, allowing arbitrary file uploads. Because uploaded files can be executed, this is a critical remote code execution path in a widely deployed web component.

9.8 CVSS 3.1 Critical CISA KEV since 26 Jan 2023 Known ransomware use EPSS 78% · top 0.4% CWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score, v2 7.5
78%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
5References, 2 tagged exploit
14 Aug 2026Last modified by NVD

Description

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable remote code execution with a public exploit, KEV listing, ransomware use, and near-maximum EPSS score.

What it is

Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 fails to properly restrict user input to the RadAsyncUpload control, allowing arbitrary file uploads. Because uploaded files can be executed, this is a critical remote code execution path in a widely deployed web component.

Impact

An unauthenticated remote attacker can upload arbitrary files and execute arbitrary code on the server, leading to full compromise of the web application and its host.

Attack surface

Reachable over the network through the RadAsyncUpload endpoint with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed application using the vulnerable control is directly reachable.

Exploitation

Listed in CISA KEV since 2023-01-26 with known ransomware campaign use, and EPSS 30-day probability is 0.777 (99.5th percentile). A public Exploit-DB entry (43874) exists, so exploitation is active and tooling is available.

What to do

  • Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP2 or later; this is the only complete fix.
  • If immediate upgrade is impossible, apply the vendor mitigation guidance for RadAsyncUpload insecure direct object reference.
  • Restrict or block external access to the RadAsyncUpload handler until patched.
  • Ensure uploaded files are stored outside the web root and cannot be executed by the application server.
  • Audit for prior compromise, given KEV ransomware association.

Detection

  • Monitor web logs for POST requests to RadAsyncUpload handler paths, especially with unusual file extensions or content types.
  • Alert on newly created files in web-accessible upload directories, particularly executable extensions.
  • Look for outbound connections or child processes spawned by the web server process (w3wp.exe) after upload activity.
  • Hunt for known Telerik exploitation patterns and webshell artifacts in upload directories.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-11357 to the Known Exploited Vulnerabilities catalog on 26 January 2023 as "Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 16 February 2023.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-11357 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-6023Progress telerik ui for asp.net ajax deserialization of untrusted data vulnerabilityIn Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when resto…EPSS 0.73%9.8CVE-2021-28141Progress telerik ui for asp.net ajax missing authorization vulnerabilityAn issue was discovered in Progress Telerik UI for ASP.NET AJAX 2021.1.224. It allows unauthorized access to MicrosoftAjax.js through the Telerik.Web…EPSS 2.2%9.8CVE-2019-19790Progress telerik ui for asp.net ajax path traversal vulnerabilityPath traversal in RadChart in Telerik UI for ASP.NET AJAX allows a remote attacker to read and delete an image with extension .BMP, .EXIF, .GIF, .ICO…EPSS 3.0%8.1CVE-2026-13185Progress telerik ui for asp.net ajax deserialization of untrusted data vulnerabilityIn Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize…EPSS 0.67%8.1CVE-2026-13186Progress telerik ui for asp.net ajax path traversal vulnerabilityIn Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploite…EPSS 0.73%8.1CVE-2026-13187Progress telerik ui for asp.net ajax vulnerabilityIn Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentially altering dialog processin…EPSS 0.47%8.1CVE-2026-13190Progress telerik ui for asp.net ajax deserialization of untrusted data vulnerabilityIn Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation…EPSS 0.67%8.1CVE-2026-13181Progress telerik ui for asp.net ajax vulnerabilityIn Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attack…EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2017-11357), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.