Web Hack List

Collected research

Remote Code Execution via Insecure Deserialization in Telerik UI

CVE-2019-18935: Remote Code Execution via Insecure Deserialization in Telerik UI

Telerik UI for ASP.NET AJAX takes the object type from its encrypted rauPostData upload parameter and hands it to JavaScriptSerializer. After breaking the hard-coded upload encryption key and uploading a mixed mode assembly DLL, an attacker names AssemblyInstaller as the type and points its Path at that DLL, so loading it runs native code and returns a reverse shell.

Record

Document
CVE-2019-18935: Remote Code Execution via Insecure Deserialization in Telerik UI
Researcher
Caleb Gross
Published by
know.bishopfox.com
Format
Advisory
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Caleb Gross, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .