CVE-2021-23758: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Summary
Ajax.NET Professional (AjaxPro) has a deserialization of untrusted data vulnerability allowing remote code execution via arbitrary .NET classes. Affected products may be end-of-life, and users are advised to discontinue use or transition to supported versions. CISA guidance requires applying mitigations and adhering to patching guidelines.
IFF Assessment
The vulnerability allows for remote code execution, which is a significant threat to defenders.
Severity
CISA KEV: Listed as actively exploited. Federal patch due: September 09, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in Ajax.NET Professional presents a critical risk for organizations still using the software, enabling remote code execution. Defenders must prioritize identifying and mitigating this flaw, especially given the potential for end-of-life products to be overlooked. Compliance with CISA's guidance on prioritizing security updates based on risk is crucial.