Oracle Bug

Overview

Security firm TantoSec has published a proof‑of‑concept exploit chain that turns an AES‑CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution (RCE). While Progress Software patched the flaws in July 2026, the release of a detailed write‑up and tooling on September 7 places a complete attack path in public hands for the first time.

Vulnerability Chain

  • CVE‑2026‑13182: AES‑CBC padding oracle in RadAsyncUpload control.
  • CVE‑2026‑13181: Unguarded type‑resolution flaw enabling arbitrary .NET type deserialization.
  • CVE‑2026‑13183: Timing‑based oracle variant when detailed errors are hidden.
  • CVE‑2026‑13184: Predictable default key in alternative attack mode.

Exploit prerequisites:

  • A page must render a RadAsyncUpload control with a server‑side handler reading upload results.
  • The application must use a non‑default encryption key (ironically recommended as hardening).

Exploit Details

  • Tooling released: TantoSec’s telerik-rau-exploit command‑line tool plus two DLL payloads (web shell and in‑memory execution).
  • Attack process: Roughly 127,000 oracle requests (~1 hour in lab conditions).
  • Privileges gained: Code execution under the IIS application pool.
  • Payload behavior: Mixed‑mode DLL executes native code immediately upon load.

Risk Context

  • No confirmed exploitation in the wild as of September 7.
  • IONIX claims to track “ongoing exploitation attempts,” but details remain unclear.
  • Historical precedent:
    • CVE‑2019‑18935 exploited by ransomware crews and nation‑state actors.
    • Still active in breaches as late as 2025, including a U.S. federal agency compromise.

Progress Patch Timeline

  • Fix shipped: July 8, 2026 (version 2026.2.708 / Q2 SP1).
  • Advisory published: July 22, 2026.
  • Public exploit released: September 7, 2026.

Defensive Guidance

Organizations should:

  • Upgrade immediately to 2026.2.708 or later, which replaces AES‑CBC with authenticated encryption.
  • Set customErrors to RemoteOnly or On to force attackers onto slower timing‑based variants.
  • Disable RadAsyncUpload handler if not required.
  • Remove custom encryption keys so the control falls back to ASP.NET machine keys with AES+HMAC.
  • Hunt behaviorally: Look for IIS worker process spawning cmd.exe, unexpected .aspx files, or DLLs in upload temp folders.

Expert in the Cloud Insight

The release of TantoSec’s exploit chain shows how academic vulnerabilities become practical threats once tooling is public. Even though exploitation requires non‑default configurations, the precedent of past Telerik flaws proves attackers will weaponize these chains quickly. The lesson is clear: patch immediately, disable unnecessary upload handlers, and monitor IIS processes for suspicious activity.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.