PatchSiren cyber security CVE debrief
CVE-2017-11357 Telerik CVE debrief
CVE-2017-11357 is an insecure direct object reference (IDOR) affecting Telerik UI for ASP.NET AJAX. CISA added it to the Known Exploited Vulnerabilities catalog and marked it as known ransomware-campaign related, so organizations using this component should treat remediation as urgent.
- Vendor
- Telerik
- Product
- User Interface (UI) for ASP.NET AJAX
- CVSS
- CRITICAL 9.8
- CISA KEV
- Listed
- Original CVE published
- 2023-01-26
- Original CVE updated
- 2023-01-26
- Advisory published
- 2023-01-26
- Advisory updated
- 2023-01-26
Who should care
Security teams, application owners, and administrators responsible for Telerik UI for ASP.NET AJAX deployments should care most. This is especially important for teams supporting legacy web applications or shared application platforms that may embed the component.
Technical summary
The vulnerability is categorized as an IDOR in Telerik UI for ASP.NET AJAX. CISA's KEV entry indicates the issue is being actively exploited and points responders to vendor instructions for updates, with NVD and the CVE record as supporting references. Defenders should focus on identifying every application instance that includes this Telerik component and confirming it is remediated.
Defensive priority
Urgent
Recommended defensive actions
- Apply vendor updates per the Telerik guidance referenced by CISA.
- Inventory all applications that use Telerik UI for ASP.NET AJAX, including legacy or embedded deployments.
- Confirm which instances are exposed in production and prioritize those first.
- Use the CISA KEV catalog and NVD entry to verify remediation guidance and any affected-version details.
- Track this vulnerability as a high-priority item because CISA lists it as known exploited and associated with ransomware campaigns.
Evidence notes
CISA's Known Exploited Vulnerabilities entry for this CVE identifies the vendor as Telerik, the product as User Interface (UI) for ASP.NET AJAX, and the vulnerability name as 'Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability.' The supplied KEV metadata lists dateAdded as 2023-01-26, dueDate as 2023-02-16, knownRansomwareCampaignUse as 'Known,' and requiredAction as 'Apply updates per vendor instructions.' Supporting official references supplied in the corpus include the CVE record and NVD entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-11357 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-11357
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-11357 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-11357
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.