LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2019-18935: Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2019-18935 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe…

CVE-2019-18935 is a deserialization of untrusted data flaw in Progress Telerik UI for ASP.NET AJAX. It can be reached through the RadAsyncUpload component and allows an attacker to achieve code execution on the server under the w3wp.exe process. Because the product is commonly embedded in ASP.NET web applications and the vulnerability has been used in ransomware operations, organizations that host or develop such applications should treat it as a high-priority risk and confirm their exposure against the vendor advisory.

How it works

This issue falls under CWE-502: deserialization of untrusted data. In broad terms, the vulnerable component accepts serialized input that is not adequately validated before it is reconstituted into objects. An attacker who can supply crafted data to the RadAsyncUpload functionality can cause the application to instantiate unexpected types or execute attacker-controlled logic. Successful abuse results in arbitrary code running in the security context of the IIS worker process (w3wp.exe). Exact request formats, serialization gadgets, or payload construction details are not provided here; defenders must obtain those from the vendor advisory and reputable technical analyses rather than relying on incomplete public summaries.

Am I affected? How to find it in your systems

Progress Telerik UI for ASP.NET AJAX is typically present in custom or commercial ASP.NET web applications that use Telerik controls for rich UI features, especially file upload. It runs on Windows servers under IIS.

If inventory is incomplete, treat any internet-facing ASP.NET application that may include Telerik controls as potentially affected until proven otherwise.

How to remediate

The primary action is to apply the updates published by Progress for Telerik UI for ASP.NET AJAX, following the vendor’s instructions exactly as required by CISA. After patching:

Confirm the precise fixed versions, upgrade paths, and any configuration changes solely against the official vendor advisory.

If you can't patch immediately

Implement compensating controls while scheduling the official update:

These measures reduce risk but do not replace the vendor update.

If your data may have been exposed

Actively exploited vulnerabilities of this class, including those with known ransomware use, frequently lead to full server compromise, data theft, or encryption. If you have evidence of exploitation or cannot rule it out, initiate incident-response procedures: isolate affected hosts, preserve logs and memory, rotate credentials, and assess lateral movement. As a quick personal check, individuals can run a free exposure scan of their email addresses against known breach data sets to determine whether their credentials or personal information already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedProgress · Telerik UI for ASP.NET AJAX
WeaknessCWE-502
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities