CVE-2021-23758: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

Summary

Ajax.NET Professional (AjaxPro) has a deserialization of untrusted data vulnerability allowing remote code execution via arbitrary .NET classes. Affected products may be end-of-life, and users are advised to discontinue use or transition to supported versions. CISA guidance requires applying mitigations and adhering to patching guidelines.

IFF Assessment

FOE

The vulnerability allows for remote code execution, which is a significant threat to defenders.

Severity

8.1 High

CISA KEV: Listed as actively exploited. Federal patch due: September 09, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in Ajax.NET Professional presents a critical risk for organizations still using the software, enabling remote code execution. Defenders must prioritize identifying and mitigating this flaw, especially given the potential for end-of-life products to be overlooked. Compliance with CISA's guidance on prioritizing security updates based on risk is crucial.

Read Full Story →