Collected research
Remote Code Execution via Insecure Deserialization in Telerik UI
CVE-2019-18935: Remote Code Execution via Insecure Deserialization in Telerik UI
Telerik UI for ASP.NET AJAX takes the object type from its encrypted rauPostData upload parameter and hands it to JavaScriptSerializer. After breaking the hard-coded upload encryption key and uploading a mixed mode assembly DLL, an attacker names AssemblyInstaller as the type and points its Path at that DLL, so loading it runs native code and returns a reverse shell.
Record
- Document
- CVE-2019-18935: Remote Code Execution via Insecure Deserialization in Telerik UI
- Researcher
- Caleb Gross
- Published by
- know.bishopfox.com
- Format
- Advisory
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Caleb Gross, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .