As cited
Copy frozen at (site build).
vulnerabilities
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE - Public Exploit Released
TantoSec released a proof-of-concept exploit that chains an AES-CBC padding oracle vulnerability in Telerik UI for ASP.NET AJAX to achieve unauthenticated remote code execution. The attack requires a specific non-default application configuration, and Progress issued a patch before the public disclosure. No active exploitation has been confirmed.
Why it matters: Organizations running Telerik UI for ASP.NET AJAX in the vulnerable configuration should verify they have applied Progress's patch to eliminate this remote code execution risk.
- Source published
- First seen by Cybersecurity Tracker