CVE-2017-9248Active Exploitation(progress / sitefinity)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Patch progress sitefinity systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.

4.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-522

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sitefinity
  • ui_for_asp.net_ajax

Threat summary

  • Active exploitation appears in 2 classified signals
  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Products
sitefinityui_for_asp.net_ajax

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-25: 3Active Exploitation · 2026-02-25: 2Patch / Workaround · 2026-02-25: 2Technical Details · 2026-02-25: 202-25
Signal classification2 categories
Active Exploitation
266.7%
Disclosure
133.3%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • mysocAi@MysocAi
    Active Exploitation

    [CRITICAL] CVE-2017-9248 Exploited in the Wild Critical vulnerability with CVSS 9.8; exploits available. CVE: CVE-2017-9248 • APT: N/A • Status: ACTIVE Requires immediate patching. #mysocAi #CyberSecurityusingAi #Vulnerability #Critica… https://strobes.co/vi/cve/CVE-2017-9248

    Post summary

    The post announces that CVE-2017-9248, a critical vulnerability with CVSS 9.8, is actively exploited in the wild and requires immediate patching.

    000000
    3 followersView on X
  • mysocAi@MysocAi
    Active Exploitation

    [HIGH] CVE-2017-9248: Critical Vulnerability in Telerik UI Flaw with CVSS 9.8; exploits available; patches released. CVE: CVE-2017-9248 • APT: N/A • Status: EXPLOITED Unpatched Telerik UI components are vulnerable to attacks. #mysocAi … https://strobes.co/vi/cve/CVE-2017-9248

    Post summary

    CVE-2017-9248 is a critical Telerik UI flaw with a CVSS score of 9.8 that is actively exploited in the wild, but patches have already been released.

    000000
    3 followersView on X
  • mysocAi@MysocAi
    Disclosure

    [CRITICAL] CVE-2017-9248: Critical Vulnerability in Telerik UI for http://ASP.NET AJAX CVE-2017-9248 allows remote code execution in Telerik UI for http://ASP.NET AJAX. CVE: CVE-2017-9248 • APT: Unknown • Status: ACTIVE Affects widely used web compon… https://strobes.co/vi/cve/CVE-2017-9248

    Post summary

    The text announces a critical remote code execution vulnerability in Telerik UI for ASP.NET AJAX, but provides no PoC, exploit, or patch details.

    000000
    3 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appprogresssitefinity---
Apptelerikui_for_asp.net_ajax---

Explore more