CVE-2017-11317: Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
Other sources
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX allows remote attackers to perform arbitrary file uploads or execute arbitrary code.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Telerik.Web.UI (Progress Telerik UI for ASP.NET AJAX)to a version that resolves this vulnerability.Fixed in R1 2017 - Upgrade
Upgrade
Telerik.Web.UI (Progress Telerik UI for ASP.NET AJAX)to a version that resolves this vulnerability.Fixed in R2 2017 SP2
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11317?
CVE-2017-11317 is considered critical due to its potential for arbitrary file uploads and remote code execution.
How do I fix CVE-2017-11317?
To fix CVE-2017-11317, upgrade to Telerik UI for ASP.NET AJAX version R1 2017 or R2 2017 SP2 or later.
What is the impact of CVE-2017-11317?
The impact of CVE-2017-11317 includes potential unauthorized file uploads and the execution of arbitrary code on the server.
Which versions are affected by CVE-2017-11317?
CVE-2017-11317 affects Telerik UI for ASP.NET AJAX versions up to 2016.3.1027 and specific versions 2017.2.503 and 2017.2.621.
Who is the vendor for CVE-2017-11317?
The vendor for CVE-2017-11317 is Telerik, which develops UI components for ASP.NET AJAX.