Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities
Contenu original affiche; la traduction localisee n'est pas encore disponible.
Ce qui s'est passé
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities
Pourquoi c'est important
The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.
Entités concernées
Voir les preuves
1 articles · 1 publication d'origine · 1 independantes
- The Hacker NewsSource primaire · Confirme · EN · 100%Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released ↗
Affirmations
- Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released Observé
Divergences
Aucune divergence importante détectée dans les preuves disponibles.
Chronologie
- Premier signalement
Mouvement de marché suivant l'événement
La réaction du marché n'est pas encore disponible pour cet actif et cette fenêtre.