Vulnerability record · CVE-2017-11357 · published 23 August 2017
CVE-2017-11357: Telerik UI for ASP.NET AJAX RadAsyncUpload unrestricted file upload
Progress · Telerik Ui For Asp.Net Ajax
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 fails to properly restrict user input to the RadAsyncUpload control, allowing arbitrary file uploads. Because uploaded files can be executed, this is a critical remote code execution path in a widely deployed web component.
Description
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable remote code execution with a public exploit, KEV listing, ransomware use, and near-maximum EPSS score.
What it is
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 fails to properly restrict user input to the RadAsyncUpload control, allowing arbitrary file uploads. Because uploaded files can be executed, this is a critical remote code execution path in a widely deployed web component.
Impact
An unauthenticated remote attacker can upload arbitrary files and execute arbitrary code on the server, leading to full compromise of the web application and its host.
Attack surface
Reachable over the network through the RadAsyncUpload endpoint with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed application using the vulnerable control is directly reachable.
Exploitation
Listed in CISA KEV since 2023-01-26 with known ransomware campaign use, and EPSS 30-day probability is 0.777 (99.5th percentile). A public Exploit-DB entry (43874) exists, so exploitation is active and tooling is available.
What to do
- Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP2 or later; this is the only complete fix.
- If immediate upgrade is impossible, apply the vendor mitigation guidance for RadAsyncUpload insecure direct object reference.
- Restrict or block external access to the RadAsyncUpload handler until patched.
- Ensure uploaded files are stored outside the web root and cannot be executed by the application server.
- Audit for prior compromise, given KEV ransomware association.
Detection
- Monitor web logs for POST requests to RadAsyncUpload handler paths, especially with unusual file extensions or content types.
- Alert on newly created files in web-accessible upload directories, particularly executable extensions.
- Look for outbound connections or child processes spawned by the web server process (w3wp.exe) after upload activity.
- Hunt for known Telerik exploitation patterns and webshell artifacts in upload directories.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-11357 to the Known Exploited Vulnerabilities catalog on 26 January 2023 as "Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 16 February 2023.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/insecure-direct-object-reference | MitigationVendor Advisory |
| https://www.exploit-db.com/exploits/43874/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.telerik.com/support/kb/aspnet-ajax/upload-%28async%29/details/insecure-direct-object-reference | MitigationVendor Advisory |
| https://www.exploit-db.com/exploits/43874/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-11357 | US Government Resource |
Track CVE-2017-11357 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-11357), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.