← Vulnerability feed

Vulnerability record · CVE-2017-9248 · published 3 July 2017

CVE-2017-9248: Telerik UI for ASP.NET AJAX and Sitefinity cryptographic key protection flaw

Progress · Sitefinity

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX (before R2 2017 SP1) and Sitefinity (before 10.0.6412.0) fails to properly protect the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey. This weak key protection lets remote attackers defeat the cryptographic protection, which can lead to a MachineKey leak and follow-on abuse such as arbitrary file upload or download, XSS, or ASP.NET ViewState compromise.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 75% · top 0.5% CWE-522 · Insufficiently protected credentials
9.8CVSS 3.1 base score, v2 7.5
75%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing, public exploit code, and very high EPSS make this an urgent, actively targeted flaw.

What it is

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX (before R2 2017 SP1) and Sitefinity (before 10.0.6412.0) fails to properly protect the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey. This weak key protection lets remote attackers defeat the cryptographic protection, which can lead to a MachineKey leak and follow-on abuse such as arbitrary file upload or download, XSS, or ASP.NET ViewState compromise.

Impact

An attacker who recovers the MachineKey can forge ViewState and other protected data, enabling arbitrary file upload or download, cross-site scripting, and broader compromise of the ASP.NET application. The CVSS 3.1 base score is 9.8 (CRITICAL) with high confidentiality, integrity, and availability impact.

Attack surface

The vulnerability is network-reachable (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), so it can be triggered directly against an exposed Telerik UI for ASP.NET AJAX or Sitefinity deployment. No authentication is needed per the CVSS vector.

Exploitation

CVE-2017-9248 is listed in CISA KEV (added 2021-11-03, due 2022-05-03) and has a public Exploit-DB entry (43873), indicating known exploitation. EPSS 30-day probability is 0.75098 (99.482 percentile), a high likelihood of exploitation activity.

What to do

  • Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP1 or later and Sitefinity to 10.0.6412.0 or later, per the vendor advisory.
  • Apply the vendor mitigation guidance in the Telerik knowledge base article on the cryptographic weakness.
  • Rotate the ASP.NET MachineKey and the Telerik.Web.UI.DialogParametersEncryptionKey after patching, since the old keys may already be exposed.
  • Restrict network exposure of Telerik UI for ASP.NET AJAX and Sitefinity endpoints to trusted networks where possible.
  • Monitor for and block exploitation attempts against Telerik dialog handler endpoints.

Detection

  • Hunt for requests to Telerik.Web.UI dialog handler endpoints (for example Telerik.Web.UI.DialogHandler.aspx) with unusual or crafted parameters.
  • Monitor for signs of ViewState tampering or forged ViewState in ASP.NET application logs.
  • Alert on unexpected file uploads or downloads and on XSS payloads targeting Telerik UI or Sitefinity components.
  • Review web server and WAF logs for known CVE-2017-9248 exploit patterns and for the Exploit-DB 43873 technique.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2017-9248 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9248 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-18935Telerik UI for ASP.NET AJAX RadAsyncUpload deserialization RCEProgress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization flaw in the RadAsyncUpload function, allowing untrusted data…KEVEPSS 100%analysed9.8CVE-2017-11317Telerik UI for ASP.NET AJAX weak encryption enables arbitrary file uploadTelerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption. Because the encr…KEVEPSS 84%analysed9.8CVE-2026-7198Progress sitefinity improper access control vulnerabilityCWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access…EPSS 0.65%9.8CVE-2023-29375Progress sitefinity unrestricted file upload vulnerabilityAn issue was discovered in Progress Sitefinity 13.3 before 13.3.7647, 14.0 before 14.0.7736, 14.1 before 14.1.7826, 14.2 before 14.2.7930, and 14.3 b…EPSS 0.82%9.8CVE-2019-17392Progress sitefinity weak password recovery vulnerabilityProgress Sitefinity 12.1 has a Weak Password Recovery Mechanism for a Forgotten Password because the HTTP Host header is mishandled.EPSS 1.1%9.8CVE-2017-15883Progress sitefinity improper authentication vulnerabilitySitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of servic…EPSS 1.9%8.8CVE-2026-7201Progress sitefinity insecure direct object reference vulnerabilityCWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, an…EPSS 0.55%8.8CVE-2017-18179Progress sitefinity improper authentication vulnerabilityProgress Sitefinity 9.1 uses wrap_access_token as a non-expiring authentication token that remains valid after a password change or a session termina…EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2017-9248), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.