Improper security restrictions in UI for ASP.NET AJAX - CVE-2017-11357

 

Improper security restrictions in UI for ASP.NET AJAX - CVE-2017-11357

Published: December 19, 2017 / Updated: January 26, 2023


Vulnerability identifier: #VU9686
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-11357
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists in Progress Telerik User Interface (UI) for ASP.NET AJAX due to use of user-supplied input by RadAsyncUpload without modification or validation. A remote attacker can upload arbitrary files and execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.


Affected software

UI for ASP.NET AJAX
HP Performance Center

How to mitigate CVE-2017-11357

Update to version 2017.2.711.


Links to Public Exploits and PoC-codes

External References

Related Security Bulletins