CVE-2017-11317

CRITICAL KEV

Telerik UI For Asp.net Ajax < 2016.3.1027 - Weak Encryption

Title source: rule

Description

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

Exploits (8)

exploitdb WORKING POC
by Paul Taylor · pythonwebappsaspx
https://www.exploit-db.com/exploits/43874
nomisec WORKING POC 182 stars
by bao7uo · remote
https://github.com/bao7uo/RAU_crypto
nomisec WORKING POC 1 stars
by 0xr2r · poc
https://github.com/0xr2r/CVE-2017-11317-auto-exploit-
nomisec SUSPICIOUS 1 stars
by KasunPriyashan · poc
https://github.com/KasunPriyashan/Telerik-UI-ASP.NET-AJAX-Exploitation
vulncheck_xdb SCANNER
remote
https://github.com/hnytgl/TelerikUI-RCE
metasploit WORKING POC EXCELLENT
by Spencer McIntyre, Paul Taylor, Markus Wulftange, Caleb Gross, Alvaro Muñoz, Oleksandr Mirosh, straightblast · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/telerik_rau_deserialization.rb

Scores

CVSS v3 9.8
EPSS 0.9197
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-04-11
VulnCheck KEV 2020-06-19
InTheWild.io 2019-05-16
ENISA EUVD EUVD-2017-2951
CWE
CWE-326
Status published
Products (3)
telerik/ui_for_asp.net_ajax 2017.2.503
telerik/ui_for_asp.net_ajax 2017.2.621
telerik/ui_for_asp.net_ajax < 2016.3.1027
Published Aug 23, 2017
KEV Added Apr 11, 2022
Tracked Since Feb 18, 2026