CVE-2017-11317
Summary
| CVE | CVE-2017-11317 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-23 17:29:00 UTC |
| Updated | 2020-10-20 22:15:00 UTC |
| Description | Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code. |
Risk And Classification
EPSS: 0.917740000 probability, percentile 0.996820000 (date 2026-04-01)
CISA KEV: Listed on 2022-04-11; due 2022-05-02; ransomware use Unknown
Problem Types: CWE-326
CISA Known Exploited Vulnerability
| Vendor | Telerik |
|---|---|
| Product | User Interface (UI) for ASP.NET AJAX |
| Name | Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2017-11317 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Telerik | Ui For Asp.net Ajax | 2017.2.503 | All | All | All |
| Application | Telerik | Ui For Asp.net Ajax | 2017.2.621 | All | All | All |
| Application | Telerik | Ui For Asp.net Ajax | 2017.2.503 | All | All | All |
| Application | Telerik | Ui For Asp.net Ajax | 2017.2.621 | All | All | All |
| Application | Telerik | Ui For Asp.net Ajax | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory | CONFIRM | psirt.global.sonicwall.com | |
| Unrestricted File Upload - Telerik - KB | CONFIRM | www.telerik.com | Mitigation, Vendor Advisory |
| Telerik UI for ASP.NET AJAX 2012.3.1308 < 2017.1.118 - Arbitrary File Upload - ASPX webapps Exploit | EXPLOIT-DB | www.exploit-db.com | |
| Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization ≈ Packet Storm | MISC | packetstormsecurity.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.