CVE-2025-3600: Unsafe Reflection Vulnerability in Telerik UI for ASP.NET AJAX
Published May 14, 2025
·Updated
In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.
Affected Software
2 affected components
Telerik UI for AJAX>=2011.2.712<=2025.1.218
Progress Telerik UI for ASP.NET AJAX>=2011.2712<=2025.1.218
Event History
May 14, 2025
CVE Published
via MITRE·01:21 PM
Data Sourced
via MITRE·01:21 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-3600?
CVE-2025-3600 has a high severity rating due to its potential to cause denial of service.
2
How do I fix CVE-2025-3600?
To fix CVE-2025-3600, update your Telerik UI for AJAX to a version later than 2025.1.218.
3
What versions of Telerik UI for AJAX are affected by CVE-2025-3600?
Telerik UI for AJAX versions from 2011.2.712 to 2025.1.218 are affected by CVE-2025-3600.
4
What type of vulnerability is CVE-2025-3600?
CVE-2025-3600 is an unsafe reflection vulnerability that may lead to unhandled exceptions.
5
What impact does CVE-2025-3600 have?
CVE-2025-3600 can lead to a crash of the hosting process, resulting in denial of service.