CVE-2017-9248 is a cryptographic weakness in Progress Telerik UI for ASP.NET AJAX, affecting Telerik.Web.UI.dll in releases before R2 2017 SP1, and Sitefinity before 10.0.6412.0. The flaw is in the protection of DialogHandler parameters, specifically the handling of DialogParametersEncryptionKey and, in some cases, exposure of material that can lead to compromise of the ASP.NET MachineKey. In vulnerable deployments, the DialogHandler parameter protection scheme is weak enough that a remote attacker can recover or defeat the effective protection on encrypted dialog parameters and gain unauthorized access to Telerik file-management functionality such as Document Manager. Public analysis describes the issue as stemming from poorly designed cryptographic protection around parameters used to initialize the file manager interface, enabling attackers to craft valid protected parameters after key recovery or equivalent cryptographic bypass. Successful exploitation can expose file browsing and file transfer capabilities and can also enable cross-site scripting and compromise of ASP.NET ViewState protections.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a Python exploit (dp_crypto.py) targeting CVE-2017-9248 in Telerik UI for ASP.NET AJAX. The exploit leverages a weak cryptographic implementation in the DialogHandler to recover the encryption key via a network oracle attack. Once the key is recovered, the tool generates a valid encrypted URL parameter ('dp'), which can be used to access the DialogHandler's file manager and upload arbitrary files (such as web shells) to the server, provided the server's file permissions allow it. The exploit is operational and automates the key recovery and payload generation process. The README provides detailed usage instructions and example output. The only code file is dp_crypto.py, which is the main entry point and implements all exploit logic. No hardcoded endpoints are present, but the tool requires the user to specify the target DialogHandler URL. The attack vector is network-based, exploiting a web application endpoint.
This repository provides an operational exploit for CVE-2017-9248, a cryptographic weakness in Telerik UI for ASP.NET AJAX. The exploit targets the DialogHandler and SpellCheckHandler endpoints, which are commonly exposed as /Telerik.Web.UI.DialogHandler.aspx and /Telerik.Web.UI.SpellCheckHandler.axd. The main script, dp_cryptomg.py, automates the process of recovering the cryptographic key used to encrypt DialogParameters by leveraging error messages and cryptanalysis. Once the key is recovered, the tool can generate a payload that interacts with the Telerik file manager utility, allowing arbitrary file uploads and typically leading to remote code execution. The repository also includes dp_manual_crypt.py for manual encryption/decryption of parameters, a test suite, and supporting libraries for terminal UI and cryptographic operations. The exploit is written in Python and is more efficient than previous tools, supporting proxying, custom cookies, and various output modes. The code is mature and operational, providing a practical attack path against unpatched Telerik UI installations.
This repository contains 'Telewreck', a Burp Suite extension written in Python (Jython) designed to detect and exploit Telerik Web UI instances vulnerable to CVE-2017-9248. The main file, telewreck.py, implements both passive detection (during Burp scans) and active exploitation by brute-forcing the cryptographic key used by vulnerable versions of Telerik Web UI. If successful, the tool can discover the Document Manager link, which may allow arbitrary file uploads. The extension provides a GUI within Burp Suite for user interaction, including specifying the target URL (defaulting to /Telerik.Web.UI.DialogHandler.aspx), selecting character sets for brute-forcing, and viewing logs. The README provides installation and usage instructions, as well as a comprehensive list of vulnerable versions. The tool is operational and can be used for both detection and exploitation, provided the target is misconfigured or running a default/vulnerable setup.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historical Telerik UI for ASP.NET AJAX remote code execution vulnerability referenced as actively exploited (per CISA).
A cryptographic weakness in Telerik UI for ASP.NET AJAX (DialogHandler) that allows attackers to deduce encryption keys and gain unauthorized access to a file upload utility, leading to remote code execution.
A cryptographic weakness in Telerik UI for ASP.NET AJAX (DialogHandler/SpellCheckHandler) where dialog parameters are protected with weak reversible encoding (Base64 + rotating XOR) and error-message oracles, enabling key recovery and subsequent abuse (notably file manager access leading to arbitrary file upload and potential RCE).
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.