Overview
Security firm TantoSec has published a proof‑of‑concept exploit chain that turns an AES‑CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution (RCE). While Progress Software patched the flaws in July 2026, the release of a detailed write‑up and tooling on September 7 places a complete attack path in public hands for the first time.
Vulnerability Chain
- CVE‑2026‑13182: AES‑CBC padding oracle in RadAsyncUpload control.
- CVE‑2026‑13181: Unguarded type‑resolution flaw enabling arbitrary .NET type deserialization.
- CVE‑2026‑13183: Timing‑based oracle variant when detailed errors are hidden.
- CVE‑2026‑13184: Predictable default key in alternative attack mode.
Exploit prerequisites:
- A page must render a RadAsyncUpload control with a server‑side handler reading upload results.
- The application must use a non‑default encryption key (ironically recommended as hardening).
Exploit Details
- Tooling released: TantoSec’s
telerik-rau-exploitcommand‑line tool plus two DLL payloads (web shell and in‑memory execution). - Attack process: Roughly 127,000 oracle requests (~1 hour in lab conditions).
- Privileges gained: Code execution under the IIS application pool.
- Payload behavior: Mixed‑mode DLL executes native code immediately upon load.
Risk Context
- No confirmed exploitation in the wild as of September 7.
- IONIX claims to track “ongoing exploitation attempts,” but details remain unclear.
- Historical precedent:
- CVE‑2019‑18935 exploited by ransomware crews and nation‑state actors.
- Still active in breaches as late as 2025, including a U.S. federal agency compromise.
Progress Patch Timeline
- Fix shipped: July 8, 2026 (version 2026.2.708 / Q2 SP1).
- Advisory published: July 22, 2026.
- Public exploit released: September 7, 2026.
Defensive Guidance
Organizations should:
- Upgrade immediately to 2026.2.708 or later, which replaces AES‑CBC with authenticated encryption.
- Set customErrors to RemoteOnly or On to force attackers onto slower timing‑based variants.
- Disable RadAsyncUpload handler if not required.
- Remove custom encryption keys so the control falls back to ASP.NET machine keys with AES+HMAC.
- Hunt behaviorally: Look for IIS worker process spawning
cmd.exe, unexpected.aspxfiles, or DLLs in upload temp folders.
Expert in the Cloud Insight
The release of TantoSec’s exploit chain shows how academic vulnerabilities become practical threats once tooling is public. Even though exploitation requires non‑default configurations, the precedent of past Telerik flaws proves attackers will weaponize these chains quickly. The lesson is clear: patch immediately, disable unnecessary upload handlers, and monitor IIS processes for suspicious activity.
Leave a Reply