Vulnerability record · CVE-2019-18935 · published 11 December 2019
CVE-2019-18935: Telerik UI for ASP.NET AJAX RadAsyncUpload deserialization RCE
Telerik · Ui For Asp.Net Ajax
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization flaw in the RadAsyncUpload function, allowing untrusted data to be deserialized. It is exploitable when the encryption keys are known, which can result from CVE-2017-11317 or CVE-2017-11357, and leads to remote code execution. The 2020.1.114 release adds a default setting that prevents the exploit.
Description
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, CISA KEV listing with known ransomware use, near-maximum EPSS probability, and public exploit code make this an urgent patch-first issue.
What it is
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization flaw in the RadAsyncUpload function, allowing untrusted data to be deserialized. It is exploitable when the encryption keys are known, which can result from CVE-2017-11317 or CVE-2017-11357, and leads to remote code execution. The 2020.1.114 release adds a default setting that prevents the exploit.
Impact
An attacker can execute arbitrary code on the server hosting the vulnerable Telerik UI component. This yields full compromise of the web application and its underlying host.
Attack surface
Reachable over the network via the RadAsyncUpload endpoint with no authentication or user interaction required per the CVSS vector. Exploitation depends on the attacker knowing the encryption keys, which may be obtained through related vulnerabilities or other means.
Exploitation
Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability is 0.99737 (99.953rd percentile). Multiple public exploit references exist, including Packet Storm, GitHub PoCs and Bishop Fox research.
What to do
- Upgrade Telerik UI for ASP.NET AJAX to 2020.1.114 or later, which enables a default setting that blocks the exploit.
- If immediate upgrade is not possible, apply the vendor workaround to disable the JavaScriptSerializer deserialization path as documented in the Telerik knowledge base.
- Rotate and protect the Telerik RadAsyncUpload encryption keys, and remediate CVE-2017-11317 and CVE-2017-11357 so keys cannot be recovered.
- Restrict network access to Telerik UI endpoints and monitor for unexpected upload or deserialization activity.
Detection
- Monitor web server and application logs for requests to RadAsyncUpload handlers with unusual or malformed payloads.
- Alert on outbound network connections or process creation from the web server process (w3wp.exe) that are not part of normal application behavior.
- Search for known exploit artifacts such as the RAU_crypto or CVE-2019-18935 tooling signatures in file uploads or HTTP traffic.
- Review for signs of post-exploitation activity consistent with ransomware deployment on hosts running the vulnerable component.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-18935 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-18935 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-18935), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.