CVE-2017-9248

CRITICAL KEV

Telerik UI <R2 2017 SP1-10.0.6412.0 - MachineKey Leak

Title source: llm

Description

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.

Exploits (10)

exploitdb WORKING POC
by Paul Taylor · pythonwebappsaspx
https://www.exploit-db.com/exploits/43873
nomisec WORKING POC 177 stars
by bao7uo · remote
https://github.com/bao7uo/dp_crypto
nomisec WORKING POC 97 stars
by capt-meelo · remote
https://github.com/capt-meelo/Telewreck
nomisec WORKING POC 61 stars
by blacklanternsecurity · remote
https://github.com/blacklanternsecurity/dp_cryptomg
nomisec SCANNER 2 stars
by 0xsharz · poc
https://github.com/0xsharz/telerik-scanner-cve-2017-9248
nomisec WORKING POC
by cehamod · remote
https://github.com/cehamod/UI_CVE-2017-9248
nomisec WORKING POC
by oldboysonnt · remote
https://github.com/oldboysonnt/dp
nomisec WORKING POC
by ictnamanh · client-side
https://github.com/ictnamanh/CVE-2017-9248
vulncheck_xdb SCANNER
remote
https://github.com/blacklanternsecurity/badsecrets

Scores

CVSS v3 9.8
EPSS 0.8859
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-10-22
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2017-18184
CWE
CWE-522
Status published
Products (2)
progress/sitefinity < 10.0.6412.0
telerik/ui_for_asp.net_ajax < 2017.2.503
Published Jul 03, 2017
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026