Telerik UI의 취약점을 이용한 원격 코드 실행 취약점이 공개되었습니다.
TantoSec이 발표한 공개적인 증명 개념은 Telerik UI for ASP.NET AJAX의 AES-CBC '패딩 오라클'을 악용하여 인증 없는 원격 코드 실행 취약점을 발생시켰습니다. 이 취약점은 특정 비기본 설정에 있는 애플리케이션에서만 영향을 미치며, Progress는 지난 7월에 이를 악용하는 경로를 수정했습니다. 현재까지 실제 악용 사례는 확인되지 않았습니다.
A remote code execution vulnerability in Telerik UI has been publicly exploited.
A proof-of-concept by TantoSec demonstrates how an AES-CBC 'padding oracle' in Telerik UI for ASP.NET AJAX can be exploited for unauthenticated remote code execution, but only against applications in a specific non-default configuration. Progress patched this vulnerability chain in July. There are no confirmed reports of exploitation in the wild.