Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

Summary

TantoSec has released a proof-of-concept exploit for a vulnerability in Telerik UI for ASP.NET AJAX. The exploit chains an AES-CBC padding oracle vulnerability to achieve unauthenticated remote code execution, but requires a specific non-default application configuration. Progress, the vendor, has already patched the vulnerability.

IFF Assessment

FOE

The release of a public exploit for a remote code execution vulnerability poses a direct threat to unpatched or misconfigured systems, making it bad news for defenders.

Severity

9.8 Critical (AI Estimated)

This vulnerability allows for unauthenticated remote code execution (RCE) through a chained exploit. The high impact (confidentiality, integrity, and availability) and exploitability (available public exploit) contribute to a high CVSS score.

Defender Context

Defenders should prioritize patching or reconfiguring applications using Telerik UI for ASP.NET AJAX to mitigate the risk of exploitation. The existence of a public exploit, even with specific configuration requirements, increases the likelihood of targeted attacks.

Read Full Story →