← Vulnerability feed

Vulnerability record · CVE-2019-18935 · published 11 December 2019

CVE-2019-18935: Telerik UI for ASP.NET AJAX RadAsyncUpload deserialization RCE

Telerik · Ui For Asp.Net Ajax

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization flaw in the RadAsyncUpload function, allowing untrusted data to be deserialized. It is exploitable when the encryption keys are known, which can result from CVE-2017-11317 or CVE-2017-11357, and leads to remote code execution. The 2020.1.114 release adds a default setting that prevents the exploit.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-502 · Deserialization of untrusted data
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
21References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, CISA KEV listing with known ransomware use, near-maximum EPSS probability, and public exploit code make this an urgent patch-first issue.

What it is

Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization flaw in the RadAsyncUpload function, allowing untrusted data to be deserialized. It is exploitable when the encryption keys are known, which can result from CVE-2017-11317 or CVE-2017-11357, and leads to remote code execution. The 2020.1.114 release adds a default setting that prevents the exploit.

Impact

An attacker can execute arbitrary code on the server hosting the vulnerable Telerik UI component. This yields full compromise of the web application and its underlying host.

Attack surface

Reachable over the network via the RadAsyncUpload endpoint with no authentication or user interaction required per the CVSS vector. Exploitation depends on the attacker knowing the encryption keys, which may be obtained through related vulnerabilities or other means.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and EPSS 30-day probability is 0.99737 (99.953rd percentile). Multiple public exploit references exist, including Packet Storm, GitHub PoCs and Bishop Fox research.

What to do

  • Upgrade Telerik UI for ASP.NET AJAX to 2020.1.114 or later, which enables a default setting that blocks the exploit.
  • If immediate upgrade is not possible, apply the vendor workaround to disable the JavaScriptSerializer deserialization path as documented in the Telerik knowledge base.
  • Rotate and protect the Telerik RadAsyncUpload encryption keys, and remediate CVE-2017-11317 and CVE-2017-11357 so keys cannot be recovered.
  • Restrict network access to Telerik UI endpoints and monitor for unexpected upload or deserialization activity.

Detection

  • Monitor web server and application logs for requests to RadAsyncUpload handlers with unusual or malformed payloads.
  • Alert on outbound network connections or process creation from the web server process (w3wp.exe) that are not part of normal application behavior.
  • Search for known exploit artifacts such as the RAU_crypto or CVE-2019-18935 tooling signatures in file uploads or HTTP traffic.
  • Review for signs of post-exploitation activity consistent with ransomware deployment on hosts running the vulnerable component.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-18935 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://packetstormsecurity.com/files/155720/Telerik-UI-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/159653/Telerik-UI-ASP.NET-AJAX-RadAsyncUpload-Deserialization.html ExploitThird Party AdvisoryVDB Entry
https://codewhitesec.blogspot.com/2019/02/telerik-revisited.html Not Applicable
https://github.com/bao7uo/RAU_crypto ExploitThird Party Advisory
https://github.com/noperator/CVE-2019-18935 ExploitThird Party Advisory
https://know.bishopfox.com/research/cve-2019-18935-remote-code-execution-in-telerik-ui ExploitThird Party Advisory
https://www.bleepingcomputer.com/news/security/us-federal-agency-hacked-using-old-telerik-bug-to-steal-data/ Press/Media Coverage
https://www.telerik.com/support/kb/aspnet-ajax/details/allows-javascriptserializer-deserialization PatchVendor Advisory
https://www.telerik.com/support/whats-new/aspnet-ajax/release-history/ui-for-asp-net-ajax-r1-2020-%28version-2020-1-114% Release Notes
https://www.telerik.com/support/whats-new/release-history Release NotesVendor Advisory
http://packetstormsecurity.com/files/155720/Telerik-UI-Remote-Code-Execution.html Third Party AdvisoryVDB Entry
http://packetstormsecurity.com/files/159653/Telerik-UI-ASP.NET-AJAX-RadAsyncUpload-Deserialization.html ExploitThird Party AdvisoryVDB Entry
https://codewhitesec.blogspot.com/2019/02/telerik-revisited.html Not Applicable
https://github.com/bao7uo/RAU_crypto ExploitThird Party Advisory
https://github.com/noperator/CVE-2019-18935 ExploitThird Party Advisory
https://know.bishopfox.com/research/cve-2019-18935-remote-code-execution-in-telerik-ui ExploitThird Party Advisory
https://www.bleepingcomputer.com/news/security/us-federal-agency-hacked-using-old-telerik-bug-to-steal-data/ Press/Media Coverage
https://www.telerik.com/support/kb/aspnet-ajax/details/allows-javascriptserializer-deserialization PatchVendor Advisory
https://www.telerik.com/support/whats-new/aspnet-ajax/release-history/ui-for-asp-net-ajax-r1-2020-%28version-2020-1-114% Release Notes
https://www.telerik.com/support/whats-new/release-history Release NotesVendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-18935 US Government Resource

Track CVE-2019-18935 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-11317Telerik UI for ASP.NET AJAX weak encryption enables arbitrary file uploadTelerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption. Because the encr…KEVEPSS 84%analysed9.8CVE-2017-9248Telerik UI for ASP.NET AJAX and Sitefinity cryptographic key protection flawTelerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX (before R2 2017 SP1) and Sitefinity (before 10.0.6412.0) fails to properly protect the Tel…KEVEPSS 75%analysed9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed8.8CVE-2026-45659Microsoft SharePoint Server deserialization flaw enables remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an authenticated attacker run code over the network. The flaw is remotely reachable,…KEVEPSS 2.7%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2019-18935), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.