Vulnerability record · CVE-2017-9248 · published 3 July 2017
CVE-2017-9248: Telerik UI for ASP.NET AJAX and Sitefinity cryptographic key protection flaw
Progress · Sitefinity
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX (before R2 2017 SP1) and Sitefinity (before 10.0.6412.0) fails to properly protect the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey. This weak key protection lets remote attackers defeat the cryptographic protection, which can lead to a MachineKey leak and follow-on abuse such as arbitrary file upload or download, XSS, or ASP.NET ViewState compromise.
Description
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing, public exploit code, and very high EPSS make this an urgent, actively targeted flaw.
What it is
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX (before R2 2017 SP1) and Sitefinity (before 10.0.6412.0) fails to properly protect the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey. This weak key protection lets remote attackers defeat the cryptographic protection, which can lead to a MachineKey leak and follow-on abuse such as arbitrary file upload or download, XSS, or ASP.NET ViewState compromise.
Impact
An attacker who recovers the MachineKey can forge ViewState and other protected data, enabling arbitrary file upload or download, cross-site scripting, and broader compromise of the ASP.NET application. The CVSS 3.1 base score is 9.8 (CRITICAL) with high confidentiality, integrity, and availability impact.
Attack surface
The vulnerability is network-reachable (AV:N) with no privileges required (PR:N) and no user interaction (UI:N), so it can be triggered directly against an exposed Telerik UI for ASP.NET AJAX or Sitefinity deployment. No authentication is needed per the CVSS vector.
Exploitation
CVE-2017-9248 is listed in CISA KEV (added 2021-11-03, due 2022-05-03) and has a public Exploit-DB entry (43873), indicating known exploitation. EPSS 30-day probability is 0.75098 (99.482 percentile), a high likelihood of exploitation activity.
What to do
- Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP1 or later and Sitefinity to 10.0.6412.0 or later, per the vendor advisory.
- Apply the vendor mitigation guidance in the Telerik knowledge base article on the cryptographic weakness.
- Rotate the ASP.NET MachineKey and the Telerik.Web.UI.DialogParametersEncryptionKey after patching, since the old keys may already be exposed.
- Restrict network exposure of Telerik UI for ASP.NET AJAX and Sitefinity endpoints to trusted networks where possible.
- Monitor for and block exploitation attempts against Telerik dialog handler endpoints.
Detection
- Hunt for requests to Telerik.Web.UI dialog handler endpoints (for example Telerik.Web.UI.DialogHandler.aspx) with unusual or crafted parameters.
- Monitor for signs of ViewState tampering or forged ViewState in ASP.NET application logs.
- Alert on unexpected file uploads or downloads and on XSS payloads targeting Telerik UI or Sitefinity components.
- Review web server and WAF logs for known CVE-2017-9248 exploit patterns and for the Exploit-DB 43873 technique.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2017-9248 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/99965 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.telerik.com/blogs/security-alert-for-telerik-ui-for-asp.net-ajax-and-progress-sitefinity | Vendor Advisory |
| http://www.telerik.com/support/kb/aspnet-ajax/details/cryptographic-weakness | MitigationVendor Advisory |
| https://www.exploit-db.com/exploits/43873/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/99965 | Broken LinkThird Party AdvisoryVDB Entry |
| http://www.telerik.com/blogs/security-alert-for-telerik-ui-for-asp.net-ajax-and-progress-sitefinity | Vendor Advisory |
| http://www.telerik.com/support/kb/aspnet-ajax/details/cryptographic-weakness | MitigationVendor Advisory |
| https://www.exploit-db.com/exploits/43873/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9248 | US Government Resource |
Track CVE-2017-9248 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-9248), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.