(Telerik UI for ASPNET AJAX), Insecure Deserialization, CVE-2019-18935 (Critical) -DC-Oct2026-3036

Listen to this Post

CVE-2019-18935 is a critical vulnerability impacting Progress Telerik UI for ASP.NET AJAX.
It affects versions spanning from 2011.1.315 up to and including 2019.3.1023.
The flaw resides specifically within the RadAsyncUpload file upload component.
This component allows users to upload asynchronous files to the server.
It handles processing via an insecure JSON deserialization mechanism.
The vulnerability stems from the use of JavaScriptSerializer to process input.
Unauthenticated attackers can supply malicious serialized objects to the handler.

The endpoint responsible for this processing is Telerik.Web.UI.WebResource.axd.

When called with the type=rau parameter, it triggers the vulnerable code path.
Attackers exploit this by sending specially crafted input to the server.
Successful exploitation requires knowledge of the machine encryption keys.
These keys can sometimes be obtained via prior vulnerabilities like CVE-2017-11317.
Alternatively, configuration weaknesses may expose or leak the necessary keys.
Once the application deserializes the untrusted data stream, code executes.
The malicious payload runs in the context of the worker process.
This typically means executing code under the IIS w3wp.exe account permissions.
An attacker achieves arbitrary remote code execution on the host machine.
This can lead to total system compromise, data theft, and persistence.
Threat actors have actively weaponized this flaw in real-world campaigns.
CISA added this specific vulnerability to its Known Exploited Vulnerabilities catalog.
Automated scanners and botnets frequently probe internet-facing endpoints for it.
Post-exploitation activities often include deploying cryptominers and web shells.
Cobalt Strike beacons have also been deployed following successful exploitation chains.
Remediation requires updating the Telerik UI components to newer versions.
Alternatively, changing internal settings can disable the vulnerable callback features.
Security teams use multi-stage detection templates to identify vulnerable systems.
These checks probe the WebResource endpoint without causing destructive side effects.
Auditing tools flag outdated versions and misconfigured upload handlers automatically.
Maintaining robust patch management prevents exposure to this critical flaw.
Understanding this mechanism is vital for modern defensive security engineering.

DailyCVE Form:

Platform: Progress Telerik UI
Version: Through 2019.3.1023
Vulnerability: Insecure .NET deserialization
Severity: Critical risk level
date: November 2019 release

Prediction: Patched in 2019

(end of form)

What Undercode Say

Bash Commands and Codes

Check for RadAsyncUpload handler availability
curl -s "http://target-server/Telerik.Web.UI.WebResource.axd?type=rau"

Exploit: (Educational Purposes!)

The exploit involves sending a crafted POST request to the WebResource endpoint containing a serialized gadget chain via the `rauPostData` parameter, leveraging known encryption keys to achieve remote code execution.

Protection: from this CVE

Upgrade Telerik UI for ASP.NET AJAX to version 2019.3.1023 or later, or apply official patches and secure configuration guidelines to restrict untrusted deserialization.

Impact:

Complete compromise of the host server, arbitrary code execution under the IIS worker process, data exfiltration, deployment of web shells, and installation of secondary malware like cryptominers.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top