CVE-2019-18935β€”Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

PUBLISHEDvulnerability record
2021-11-03 Β· last modified June 21, 2025

Metadata

CVE ID:
CVE-2019-18935
Project:
Progress
Product:
Telerik UI for ASP.NET AJAX
Date Added:
2021-11-03
Due Date:
2022-05-03
Last Updated:
June 21, 2025

Vulnerability Name

Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability

Description

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply updates per vendor instructions.

Additional Notes

Related News Articles

Related Weaknesses