FortiGuard
Fortinet’s Global Threat Intelligence and Research
Pwalia
Staff
Staff
Article Id 248750
Description Versions prior to R1 2020 (2020.1.114) are susceptible to remote code execution attacks on affected web servers of Telerik User Interface (UI) for ASP-NET due to a deserialization vulnerability found in RadAsyncUpload function. FortiGuard Labs continue seeing high exploitation activity of these old vulnerabilities.
CVEs CVE-2019-18935CVE-2017-11317CVE-2017-11357
Severity High
Posted on Mar 09, 2023
Outbreak Report Link https://www.fortiguard.com/outbreak-alert/progress-telerik-ui-attack
Contributors