LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-9248: Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-9248 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Progress Telerik UI for ASP.NET AJAX and Sitefinity have a cryptographic weakness in Telerik.Web.UI.dll that can be exploited to disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey…

CVE-2017-9248 is a cryptographic weakness in Progress Telerik UI for ASP.NET AJAX and Sitefinity, specifically in Telerik.Web.UI.dll. An attacker who can exploit it may disclose encryption keys (Telerik.Web.UI.DialogParametersEncryptionKey and/or the MachineKey), carry out cross-site scripting (XSS), compromise ASP.NET ViewState, and upload or download files. For teams running these components on internet-facing or internal web applications, the issue matters because key disclosure and file access can lead to broader application compromise. Confirm exact product scope and fixed builds against the vendor advisory.

How it works

The weakness is classed as CWE-522 (insufficiently protected credentials). In this product family, cryptographic material used to protect dialog parameters and related ASP.NET mechanisms is inadequately safeguarded inside Telerik.Web.UI.dll. An attacker who can interact with the affected UI endpoints may obtain the DialogParametersEncryptionKey and/or the MachineKey. With those secrets, the attacker can forge or decrypt protected values, inject script (XSS), tamper with ViewState, and perform unauthorized file upload or download through the component’s dialog and handler functionality. Public detail on exact request sequences is limited; treat any unauthenticated or weakly authenticated access to Telerik handlers as high risk and validate behavior only against the vendor’s description.

Am I affected? How to find it in your systems

Progress Telerik UI for ASP.NET AJAX commonly appears in custom .NET web applications; Sitefinity is a full CMS that embeds the same UI stack. Both typically run on IIS under ASP.NET.

How to remediate

Patch first. Apply the updates Progress supplies for Telerik UI for ASP.NET AJAX and for Sitefinity exactly as described in the vendor advisory and in CISA’s direction to apply updates per vendor instructions. After patching:

If you can't patch immediately

Reduce exposure until the vendor update can be deployed:

If your data may have been exposed

Actively exploited cryptographic and file-access flaws can lead to web-shell placement, data theft, or further lateral movement. If you have evidence of exploitation or cannot rule it out, follow your incident-response process: isolate hosts, preserve logs, rotate secrets, and assess uploaded files and content stores for tampering. Ransomware use is not documented for this CVE. As a routine check, you can run a free exposure scan of your email addresses against known breach data to see whether credentials or personal information have appeared in prior incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedProgress · ASP.NET AJAX and Sitefinity
WeaknessCWE-522
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities