CVE-2021-23758: Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Other sources
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/AjaxNetProfessionalto a version that resolves this vulnerability.Fixed in 21.11.29.1
Event History
Frequently Asked Questions
Which deployments are affected?
All versions of the ajaxpro.2 package are vulnerable. The affected software identifiers include Ajax.NET Professional/AjaxPro and the NuGet package AjaxNetProfessional.
What does an attacker need to exploit this issue?
The CVSS vector indicates exploitation can be performed remotely with low attack complexity, no privileges, and no user interaction. The issue arises from deserialization of arbitrary .NET classes and can lead to remote code execution.
Is this vulnerability being exploited?
Yes. It is flagged as exploited and was added to the KEV list on 2026-08-26.
What should teams do if they use Ajax.NET Professional?
Users are advised to discontinue use or transition to a supported version, as impacted products may be end-of-life or end-of-service. The provided data states that all ajaxpro.2 versions are vulnerable.