Unsafe Reflection in Progress Telerik UI for ASP.NET AJAX Can Crash the Hosting Process

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

Overview

Original source data

In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.

Affected products and scope

  • Progress Software Telerik UI for ASP.NET AJAX: The normalized affected fact starts at 2011.2.712 and covers versions < 2025.1.416; default status is set to unaffected outside the stated affected range.
  • The vendor advisory specifically identifies versions from 2011.2.712 through 2025.1.218 inclusive as affected and identifies 2025.1.416 as the patched target.
  • Because the normalized upper boundary and the vendor's enumerated range are expressed differently, releases between 2025.1.218 and 2025.1.416 are not separately characterized in the advisory. Do not assume those releases are safe; follow the vendor's current release guidance.

Technical details

The vulnerability is classified as CWE-470, the use of externally controlled input to select classes or code, also called unsafe reflection. The vendor states that an attacker can send a specially crafted request to an application using Telerik UI for ASP.NET AJAX. The request can trigger unsafe reflection handling and lead to an unhandled exception. The exception crashes the hosting process, causing denial of service while the application restarts.

The vendor's verification steps associate the vulnerable behavior with Telerik.Web.UI.dll and handlers serving Telerik.Web.UI.WebResource.axd in web.config. The available record does not disclose the exact reflection target, the complete input structure, or deployment conditions beyond network reachability.

Exploitability

  • Reachability: The issue can be triggered remotely through a network request to an affected application.
  • Authentication and interaction: The supplied record describes no required privileges and no user interaction.
  • Complexity: The supplied record describes low attack complexity.
  • Exploitation status: The record sets public exploit to false and does not identify known exploitation activity. This does not prove that exploitation has never occurred.

Technical impact

The confirmed technical outcome is a hosting-process crash and denial of service, with no change of scope to another security authority. Because the request can arrive over the network and the record describes no required privileges, publicly reachable applications with the relevant endpoint may be disrupted remotely. The record does not establish code execution, data disclosure, or data modification. The duration of service impact depends on the hosting environment's restart and recovery behavior.

Business impact

The confirmed effect is loss of application availability for Telerik UI for ASP.NET AJAX deployments. A successful request can terminate the hosting process and interrupt service while the application restarts. Repeated requests could prolong the interruption, but the record does not establish persistence or resource impact beyond the process crash. The record does not identify a confidentiality or integrity consequence.

Remediation

  1. Upgrade Telerik UI for ASP.NET AJAX to 2025.1.416 (2025 Q1 SP2), the patched target specified by the vendor. The vendor's table expresses the fixed boundary as >= v2025.1.416; verify the deployed assembly after upgrading.
  2. If an immediate upgrade is not possible, use one of the temporary mitigations documented by the vendor. An assembly binding redirect loads patched assemblies and is guaranteed by the vendor only for applications using 2024.2 or later; the vendor also lists conditions to consider for older branches.
  3. The vendor also documents an HTTP Request Filtering Module and URL Rewrite for all affected versions. Implement these measures according to the vendor's instructions and test them before production deployment.
  4. After changing web.config, perform a controlled application restart. Configuration changes may trigger an IIS restart, but the vendor recommends restarting the application manually without delay.
  5. Prioritize instances reachable from untrusted networks, and verify that every copy of the assembly in build artifacts and deployment directories has been replaced.

Detection

  1. Inventory source projects and deployed binaries for the Telerik.Web.UI.dll assembly.
  2. Read the assembly version from Visual Studio reference properties or equivalent deployment metadata, then compare it with the affected and fixed boundaries in affected_summary.
  3. Inspect web.config for registration of Telerik.Web.UI.WebResource.axd under httpHandlers or the system.webServer handler collection.
  4. Review application logs, hosting logs, and process-supervision telemetry for unhandled exceptions, hosting-process crashes, and restarts near requests to the affected handler. These are behavioral checks, not vendor-defined IOCs.
  5. As a precautionary review, inspect logged requests to the handler and the type and prtype parameters referenced in the vendor's mitigation logic. Absence of these events does not prove that the system is safe.
Sources (16)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan