vendor:
Telerik UI
by:
Bishop Fox
9.8
CVSS
CRITICAL
Insecure Deserialization
502
CWE
Product Name: Telerik UI
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: CVE-2019-18935
CPE: N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
CVE-2019-18935: Remote Code Execution in Telerik UI
This vulnerability allows an attacker to execute arbitrary code on the target server by exploiting an insecure deserialization vulnerability in Telerik UI. The attacker can upload a malicious DLL to the target server and then load it into the application via the insecure deserialization exploit.
Mitigation:
The best way to mitigate this vulnerability is to install the module within a virtual environment and use build_dll.bat to generate 32- and 64-bit mixed mode assembly DLLs to be used as a payload during deserialization.