$ techbeacon▋
CVE & Exploits

Critical Telerik UI Flaw Enables Unauthenticated Remote Code Execution via Padding Oracle

Critical Telerik UI Flaw Enables Unauthenticated Remote Code Execution via Padding Oracle

Security researchers have uncovered a serious vulnerability chain affecting Progress Telerik UI for ASP.NET AJAX, a component widely used to build interactive web interfaces.

The flaw allows an attacker without any credentials to exploit a cryptographic padding‑oracle weakness in the library’s handling of AES‑CBC encrypted data. By repeatedly probing the server’s responses, the attacker can recover encryption keys and ultimately inject malicious code, achieving remote code execution on any application that exposes the vulnerable component.

The discovery, detailed in a report by Tanto Security and initially reported by the GBHackers community, demonstrates how a seemingly isolated cryptographic issue can be escalated into full‑blown code execution. The chain relies on the fact that Telerik’s UI components decrypt incoming data without sufficient integrity checks, exposing detailed error messages that act as an oracle for the attacker.

Telerik UI for ASP.NET AJAX is integrated into thousands of enterprise and public‑sector websites, ranging from internal dashboards to customer‑facing portals. Because the vulnerability can be triggered without authentication, any publicly reachable endpoint that processes Telerik‑generated requests becomes a potential foothold for malicious actors. Successful exploitation could lead to data theft, defacement, or the deployment of ransomware across the compromised server.

Progress, the company behind Telerik, has acknowledged the issue and is working on a patch. In the meantime, the security advisory recommends immediate mitigation steps: disabling the vulnerable component where possible, applying strict input validation, and configuring the web server to suppress detailed error messages that could aid an oracle attack. Organizations are also urged to review their dependency management practices to ensure that older versions of Telerik UI are promptly updated.

Experts note that the incident highlights broader challenges in third‑party UI libraries, where cryptographic operations are often bundled with UI logic. The lack of thorough security review for such components can leave applications exposed, even when the surrounding code follows best practices. As supply‑chain risks continue to rise, security teams are expected to increase scrutiny of third‑party frameworks.

Industry observers anticipate that the upcoming patch will address both the padding‑oracle weakness and the subsequent code‑execution path. However, the window for exploitation remains open until updates are applied, and attackers may already be scanning for vulnerable installations. Organizations that cannot update immediately should consider network‑level defenses, such as web application firewalls that can block anomalous request patterns associated with oracle probing.

The Telerik vulnerability serves as a reminder that even mature, commercial UI toolkits can harbor critical flaws. Continuous monitoring, rapid patch deployment, and a defense‑in‑depth strategy are essential to mitigate the risk of unauthenticated remote code execution in modern web applications.

Source: GBHackers
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related