Overview
Original source dataIn Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.
Affected products and scope
- Progress Software Telerik UI for ASP.NET AJAX: The normalized affected fact starts at
2011.2.712and covers versions< 2025.1.416; default status is set to unaffected outside the stated affected range. - The vendor advisory specifically identifies versions from
2011.2.712through2025.1.218inclusive as affected and identifies2025.1.416as the patched target. - Because the normalized upper boundary and the vendor's enumerated range are expressed differently, releases between
2025.1.218and2025.1.416are not separately characterized in the advisory. Do not assume those releases are safe; follow the vendor's current release guidance.
Technical details
The vulnerability is classified as CWE-470, the use of externally controlled input to select classes or code, also called unsafe reflection. The vendor states that an attacker can send a specially crafted request to an application using Telerik UI for ASP.NET AJAX. The request can trigger unsafe reflection handling and lead to an unhandled exception. The exception crashes the hosting process, causing denial of service while the application restarts.
The vendor's verification steps associate the vulnerable behavior with Telerik.Web.UI.dll and handlers serving Telerik.Web.UI.WebResource.axd in web.config. The available record does not disclose the exact reflection target, the complete input structure, or deployment conditions beyond network reachability.
Exploitability
- Reachability: The issue can be triggered remotely through a network request to an affected application.
- Authentication and interaction: The supplied record describes no required privileges and no user interaction.
- Complexity: The supplied record describes low attack complexity.
- Exploitation status: The record sets public exploit to false and does not identify known exploitation activity. This does not prove that exploitation has never occurred.
Technical impact
The confirmed technical outcome is a hosting-process crash and denial of service, with no change of scope to another security authority. Because the request can arrive over the network and the record describes no required privileges, publicly reachable applications with the relevant endpoint may be disrupted remotely. The record does not establish code execution, data disclosure, or data modification. The duration of service impact depends on the hosting environment's restart and recovery behavior.
Business impact
The confirmed effect is loss of application availability for Telerik UI for ASP.NET AJAX deployments. A successful request can terminate the hosting process and interrupt service while the application restarts. Repeated requests could prolong the interruption, but the record does not establish persistence or resource impact beyond the process crash. The record does not identify a confidentiality or integrity consequence.
Remediation
- Upgrade Telerik UI for ASP.NET AJAX to
2025.1.416(2025 Q1 SP2), the patched target specified by the vendor. The vendor's table expresses the fixed boundary as>= v2025.1.416; verify the deployed assembly after upgrading. - If an immediate upgrade is not possible, use one of the temporary mitigations documented by the vendor. An assembly binding redirect loads patched assemblies and is guaranteed by the vendor only for applications using
2024.2or later; the vendor also lists conditions to consider for older branches. - The vendor also documents an HTTP Request Filtering Module and URL Rewrite for all affected versions. Implement these measures according to the vendor's instructions and test them before production deployment.
- After changing
web.config, perform a controlled application restart. Configuration changes may trigger an IIS restart, but the vendor recommends restarting the application manually without delay. - Prioritize instances reachable from untrusted networks, and verify that every copy of the assembly in build artifacts and deployment directories has been replaced.
Detection
- Inventory source projects and deployed binaries for the
Telerik.Web.UI.dllassembly. - Read the assembly version from Visual Studio reference properties or equivalent deployment metadata, then compare it with the affected and fixed boundaries in
affected_summary. - Inspect
web.configfor registration ofTelerik.Web.UI.WebResource.axdunderhttpHandlersor thesystem.webServerhandler collection. - Review application logs, hosting logs, and process-supervision telemetry for unhandled exceptions, hosting-process crashes, and restarts near requests to the affected handler. These are behavioral checks, not vendor-defined IOCs.
- As a precautionary review, inspect logged requests to the handler and the
typeandprtypeparameters referenced in the vendor's mitigation logic. Absence of these events does not prove that the system is safe.