Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
oracle
1 Posts 1 Posters 5 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    TantoSec has published a working proof-of-concept that chains an AES-CBC padding oracle flaw in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution. The exploit targets a specific, non-default configuration, and Progress released a patch for the underlying chain back in July. As of now, there are no confirmed reports of in-the-wild exploitation.

    The attack hinges on a cryptographic weakness in the Telerik UI component's handling of encrypted data. By repeatedly sending crafted requests and observing the server's padding-error responses, an attacker can decrypt sensitive payloads without valid credentials. TantoSec's research demonstrates how this oracle can then be leveraged to forge a malicious request, ultimately achieving code execution on the target server.

    It is important to note that this exploit does not affect every deployment. The attack only succeeds against applications that are using a configuration which is not the default. Organizations running standard, out-of-the-box settings are not exposed to this specific chain. Administrators should verify their deployment configuration against the guidance provided in the July advisory from Progress.

    Given the severity of potential unauthenticated RCE, immediate action is recommended for affected users:

    • Apply the latest patches released by Progress in July if you have not already done so.
    • Review your Telerik UI for ASP.NET AJAX configuration to confirm whether you are running the vulnerable non-default setup.
    • Monitor for any unsolicited encrypted payloads or anomalous network traffic directed at web servers, as padding-oracle attacks generate distinctive error patterns.

    Source: The Hacker News

    Has your team audited your Telerik UI deployments to confirm whether they fall into that non-default configuration, or are you waiting on the patch cycle to catch up?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World