Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-18935

99
FAUCET Score

CVE-2019-18935 is a critical .NET deserialization vulnerability in the RadAsyncUpload function of Progress Telerik UI for ASP.NET AJAX versions through 2019.3.1023. This flaw allows for remote code execution when encryption keys are known, often due to prior vulnerabilities. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a severe risk. It is actively exploited, listed in the KEV catalog, and has publicly available exploit modules, including in Metasploit, demonstrating significant community and media attention.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2011.1.315, <= 2020.1.114CPE matchmatch criteria
cpe:2.3:a:telerik:ui_for_asp.net_ajax:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.74%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Nov 3, 2021
Metasploit: Telerik UI ASP.NET AJAX RadAsyncUpload Deserialization · Dec 9, 2019
ExploitDB: EDB-47793 · Dec 18, 2019
This CVE's current EPSS score of 0.9974 is in the 100th percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

azurevendor investigatingvia llm_extracted
Fixed in: 15.7
dotnetvendor investigatingvia llm_extracted
langgeniusvendor investigatingvia llm_extracted
phoenix_contactvendor investigatingvia llm_extracted

Vendor Advisories (4)

langgeniusllm-langgenius-98f65dc57aed9912CRITICAL

GFI Archiver v15.7 Multiple vulnerabilities

Jun 10, 2025
dotnetllm-dotnet-6c5c272c312c46ecCRITICAL

GFI Archiver v15.7 Multiple vulnerabilities

Jun 10, 2025
azurellm-azure-b7c7b2b7782bb54cCRITICAL

GFI Archiver v15.7 Multiple vulnerabilities

Jun 10, 2025
phoenix_contactllm-phoenix_contact-a52edad4e7c222c4CRITICAL

GFI Archiver v15.7 Multiple vulnerabilities

Jun 10, 2025

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
packetstormsecurity.com / files/155720/Telerik-UI-Remote-Code-Execution.html
Third Party AdvisoryVDB Entry
packetstormsecurity.com / files/159653/Telerik-UI-ASP.NET-AJAX-RadAsyncUpload-Deserialization.html
ExploitThird Party AdvisoryVDB Entry
codewhitesec.blogspot.com / 2019/02/telerik-revisited.html
Not Applicable
github.com / bao7uo/RAU_crypto
ExploitThird Party Advisory
github.com / noperator/CVE-2019-18935
ExploitThird Party Advisory
know.bishopfox.com / research/cve-2019-18935-remote-code-execution-in-telerik-ui
ExploitThird Party Advisory
bleepingcomputer.com / news/security/us-federal-agency-hacked-using-old-telerik-bug-to-steal-data
Press/Media Coverage
telerik.com / support/kb/aspnet-ajax/details/allows-javascriptserializer-deserialization
PatchVendor Advisory
telerik.com / support/whats-new/aspnet-ajax/release-history/ui-for-asp-net-ajax-r1-2020-%28version-2020-1-114%29
Release Notes
telerik.com / support/whats-new/release-history
Release NotesVendor Advisory