January 26, 2023 · Applied Cybernetics Group
CVE-2017-11357 — Telerik User Interface (UI) for ASP.NET AJAX
known ransomware use
Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability
- Added to KEV
2023-01-26- Federal due date
2023-02-16- Vendor
- Telerik
- Product
- User Interface (UI) for ASP.NET AJAX
- EPSS
- 99.5th percentile (score 0.777, as of
2026-09-16) - NVD CVSS v3.1
- 9.8 (CRITICAL)
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2017-11357
CISA short description
Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.
Required action
Apply updates per vendor instructions.
NVD description
Progress Telerik UI for ASP.NET AJAX before R2 2017 SP2 does not properly restrict user input to RadAsyncUpload, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.