Lyrie
Active Exploitation
ACTIVELY EXPLOITED3 sources verified·1 min read
By Lyrie Threat Intelligence·1/26/2023

CVE-2017-11357 added to CISA KEV: Telerik User Interface (UI) for ASP.NET AJAX

Status: ✅ Confirmed exploited in the wild

Date added: 2023-01-26

Required action: Apply updates per vendor instructions.

Due date: 2023-02-16

Why this matters

Telerik UI for ASP.NET AJAX contains an insecure direct object reference vulnerability in RadAsyncUpload that can result in file uploads in a limited location and/or remote code execution.

Sources

Lyrie Verdict

Lyrie's autonomous detection layer catches active exploitation primitives at machine speed — closing the gap between disclosure and weaponization that traditional defense simply can't cover.