CVE-2017-9248
CRITICAL KEVTelerik UI <R2 2017 SP1-10.0.6412.0 - MachineKey Leak
Title source: llmDescription
Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.
Exploits (10)
nomisec
WORKING POC
61 stars
by blacklanternsecurity · remote
https://github.com/blacklanternsecurity/dp_cryptomg
References (5)
Scores
CVSS v3
9.8
EPSS
0.8859
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CISA KEV
2021-11-03
VulnCheck KEV
2020-10-22
InTheWild.io
2021-07-23
ENISA EUVD
EUVD-2017-18184
CWE
CWE-522
Status
published
Products (2)
progress/sitefinity
< 10.0.6412.0
telerik/ui_for_asp.net_ajax
< 2017.2.503
Published
Jul 03, 2017
KEV Added
Nov 03, 2021
Tracked Since
Feb 18, 2026