Back to all lessons
Awareness Lessons
last month

Public Exploit Raises Stakes for Unpatched Telerik UI Installations

A proof-of-concept exploit chain has been publicly released targeting Telerik UI for ASP.NET AJAX, enabling unauthenticated remote code execution by chaining an AES-CBC padding oracle vulnerability. Although Progress Software issued patches in July, organizations that have not applied them are now at significantly elevated risk due to the public availability of a ready-to-use exploit tool. The vulnerability is triggered by a non-default configuration, highlighting how insecure or legacy configuration choices can expand attack surface in widely deployed third-party UI components. Public exploit releases dramatically compress the window between patch availability and active exploitation, meaning delayed patching is no longer a tolerable risk posture. This incident underscores the danger of relying on obscurity when a vendor patch already exists.

Tactical Insight

Immediate actions

  • Apply the Progress Software patch released in July immediately to all instances of Telerik UI for ASP.NET AJAX across your environment.
  • Audit all deployments for the non-default configuration that enables the vulnerable code path and remediate or disable it where the patch cannot be applied immediately.
  • Use a web application firewall (WAF) rule to detect and block padding-oracle and suspicious serialization request patterns targeting Telerik endpoints.

Long-term improvements

  • Maintain a comprehensive, up-to-date software bill of materials (SBOM) that includes all third-party UI libraries and components to enable rapid identification of affected systems during future disclosures.
  • Establish an SLA-driven emergency patching process that mandates critical vulnerability remediation within 24–72 hours for internet-facing systems.
  • Enforce hardened, documented baseline configurations for all third-party components and validate them continuously through configuration scanning tools.

Detection measures

  • Deploy runtime application self-protection (RASP) or enhanced logging on ASP.NET applications to detect anomalous deserialization or unexpected code execution attempts.
  • Configure SIEM alerting for unusual HTTP response patterns (e.g., padding-oracle timing anomalies) on web application endpoints.
  • Subscribe to vendor security advisories and threat intelligence feeds to receive advance warning of newly published exploit code for products in your environment.