CVE-2019-18935
KEV RANSOMWARECRITICAL 9.8EPSS 99.7%
Progress Telerik UI for ASP.NET AJAX through 2019.3.1023 contains a .NET deserialization vulnerability in the RadAsyncUpload function. This is exploitable when the encryption keys are known due to the presence of CVE-2017-11317 or CVE-2017-11357, or other means. Exploitation can result in remote code execution. (As of 2020.1.114, a default setting prevents the exploit. In 2019.3.1023, but not earlier versions, a non-default setting can prevent exploitation.)
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 99.74% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- critical · CWE-502
- Published
- 2019-12-11
- Updated
- 2025-10-21
Proof-of-concept exploits (20)
- http://packetstormsecurity.com/files/159653/Telerik-UI-ASP.NET-AJAX-RadAsyncUpload-Deseri…
- noperator/CVE-2019-18935374★ · 2022-04-14
- 1amUnvalid/Telerik-UI-Exploit0★ · 2021-12-18
- KasunPriyashan/Telerik-UI-ASP.NET-AJAX-Exploitation1★ · 2022-10-13
- ThanHuuTuan/CVE_2019_189352★ · 2020-05-29
- ThanHuuTuan/Telerik_CVE-2019-1893512★ · 2023-05-10
- appliedi/Telerik_CVE-2019-189350★ · 2020-07-22
- bao7uo/RAU_crypto180★ · 2020-08-22
- becrevex/Telerik_CVE-2019-189350★ · 2021-01-21
- dust-life/CVE-2019-18935-memShell13★ · 2024-11-25
- ekkoo-z/CVE-2019-18935-bypasswaf8★ · 2025-08-08
- ghostr00tt/test0★ · 2022-02-14
- hnytgl/TelerikUI-RCE2★ · 2026-06-06
- luuquy/DecryptRawdata_CVE_2019_189350★ · 2020-10-21
- murataydemir/CVE-2019-1893516★ · 2020-08-25
- quyt0/CVE-2019-18935-exploit-study1★ · 2025-09-11
- random-robbie/CVE-2019-189355★ · 2020-09-30
- rishaldwivedi/Public_Disclosure1★ · 2021-09-23
- alanbarret/CVE-2019-18935
- menashe12346/CVE-2019-18935