Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
Overview
A recent proof-of-concept by security firm TantoSec has demonstrated how a vulnerability in Telerik UI for ASP.NET AJAX can be exploited to achieve unauthenticated remote code execution (RCE). This exploit takes advantage of a 'padding oracle' issue with AES-CBC encryption, but it's important to note that it only affects applications configured in a specific, non-default way. Progress, the vendor of Telerik, patched this vulnerability back in July, and so far, there are no confirmed reports of this exploit being used in real-world attacks. Organizations using Telerik UI should ensure their configurations are secure and apply any relevant updates to mitigate potential risks.
Key Takeaways
- Affected Systems: Telerik UI for ASP.NET AJAX, specifically in non-default configurations.
- Action Required: Progress patched the vulnerabilities in July 2023.
- Timeline: Disclosed in October 2023
Original Article Summary
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities
Impact
Telerik UI for ASP.NET AJAX, specifically in non-default configurations.
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Disclosed in October 2023
Remediation
Progress patched the vulnerabilities in July 2023. Users should review their configurations and apply the latest updates from Progress to ensure security.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Exploit, Vulnerability, RCE, and 1 more.