{"cveID":"CVE-2019-18935","vendorProject":"Progress","product":"Telerik UI for ASP.NET AJAX","vulnerabilityName":"Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability","dateAdded":"2021-11-03","shortDescription":"Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2019-18935","cwes":["CWE-502"],"year":2019,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2019-18935","technique":"T1190","technique_name_at_mapping":"Exploit Public-Facing Application","mapping_type":"exploitation_technique","capability_group":"untrusted_data","comments":"CVE 2019-18935 is a Insecure Deserialization vulnerability with the Telerik UI, which does not properly sanitize serialized data inputs from the user. This vulnerability leads to the application being vulnerable to RCE attacks that may lead to a full system compromise. ","references":["https://www.bleepingcomputer.com/news/security/us-federal-agency-hacked-using-old-telerik-bug-to-steal-data/","https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-18935","technique":"T1041","technique_name_at_mapping":"Exfiltration Over C2 Channel","mapping_type":"primary_impact","capability_group":"untrusted_data","comments":"CVE 2019-18935 is a Insecure Deserialization vulnerability with the Telerik UI, which does not properly sanitize serialized data inputs from the user. This vulnerability leads to the application being vulnerable to RCE attacks that may lead to a full system compromise. ","references":["https://www.bleepingcomputer.com/news/security/us-federal-agency-hacked-using-old-telerik-bug-to-steal-data/","https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-18935","technique":"T1496","technique_name_at_mapping":"Resource Hijacking","mapping_type":"primary_impact","capability_group":"untrusted_data","comments":"CVE 2019-18935 is a Insecure Deserialization vulnerability with the Telerik UI, which does not properly sanitize serialized data inputs from the user. This vulnerability leads to the application being vulnerable to RCE attacks that may lead to a full system compromise. ","references":["https://www.bleepingcomputer.com/news/security/us-federal-agency-hacked-using-old-telerik-bug-to-steal-data/","https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2019-18935","technique":"T1505.003","technique_name_at_mapping":"Web Shell","mapping_type":"primary_impact","capability_group":"untrusted_data","comments":"CVE 2019-18935 is a Insecure Deserialization vulnerability with the Telerik UI, which does not properly sanitize serialized data inputs from the user. This vulnerability leads to the application being vulnerable to RCE attacks that may lead to a full system compromise. ","references":["https://www.bleepingcomputer.com/news/security/us-federal-agency-hacked-using-old-telerik-bug-to-steal-data/","https://news.sophos.com/en-us/2022/06/15/telerik-ui-exploitation-leads-to-cryptominer-cobalt-strike-infections/","https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-209a"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1041","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exfiltration Over C2 Channel","name_at_mapping":"Exfiltration Over C2 Channel","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":5,"has_detection_strategy":true},{"id":"T1190","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Exploit Public-Facing Application","name_at_mapping":"Exploit Public-Facing Application","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":149,"has_detection_strategy":true},{"id":"T1496","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Resource Hijacking","name_at_mapping":"Resource Hijacking","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":13,"has_detection_strategy":true},{"id":"T1505.003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Web Shell","name_at_mapping":"Web Shell","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":35,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"full","sigma_rules_tagged_cve":[],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}