Security Researchers Reveal Unauthenticated RCE Chain in Telerik UI, Vendor Issues Patch
A proof-of-concept demonstrated by security firm TantoSec shows that a padding‑oracle vulnerability in Telerik UI for ASP.NET AJAX can be leveraged to achieve unauthenticated remote code execution, but only when the component is deployed with a particular, non‑default configuration.
The flaw stems from the way the library processes AES‑CBC encrypted data. By repeatedly submitting crafted ciphertexts, an attacker can infer padding validity and gradually recover plaintext, a classic padding‑oracle scenario. TantoSec’s demonstration extends this technique to inject malicious payloads that execute on the server, effectively turning a cryptographic weakness into a code‑execution vector.
Progress Software, the maintainer of Telerik UI, addressed the issue in a July update that disables the vulnerable code path and reinforces input validation. The patch was released after the vulnerability was publicly disclosed, and the vendor has urged customers to apply the update promptly. According to the advisory, the exploit only works when developers enable a specific optional setting that is not turned on in a typical installation.
There are currently no confirmed incidents of the chain being used in the wild, and no known attackers have reported successful exploitation against live sites. Nonetheless, security analysts caution that any application that has adopted the non‑default configuration remains at risk until the patch is applied. Organizations using Telerik UI are advised to review their deployment settings, verify that the vulnerable option is disabled, and confirm that they are running the latest version of the library.
The discovery underscores a broader challenge for developers who integrate third‑party UI components: cryptographic defaults may appear convenient, but they can introduce subtle attack surfaces if not carefully managed. As supply‑chain security continues to dominate industry discussions, experts recommend regular audits of third‑party code, timely application of security updates, and adherence to best‑practice configurations to mitigate similar risks in the future.
Comments (0)
Be the first to comment.
Join the discussion