{
  "id": "CVE-2017-9248",
  "url": "https://spydr.io/cve/CVE-2017-9248",
  "published": "2017-07-03T19:29:00.270Z",
  "modified": "2026-06-17T01:27:44.860Z",
  "score": 9.8,
  "severity": "critical",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.75098,
  "epss_percentile": 0.995,
  "exploited": true,
  "kev": {
    "added": "2021-11-03",
    "due": "2022-05-03",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2017-9248"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "progress",
    "telerik"
  ],
  "products": [
    "progress sitefinity",
    "telerik ui for asp.net ajax"
  ],
  "cwes": [
    "CWE-522"
  ],
  "description": "Telerik.Web.UI.dll in Progress Telerik UI for ASP.NET AJAX before R2 2017 SP1 and Sitefinity before 10.0.6412.0 does not properly protect Telerik.Web.UI.DialogParametersEncryptionKey or the MachineKey, which makes it easier for remote attackers to defeat cryptographic protection mechanisms, leading to a MachineKey leak, arbitrary file uploads or downloads, XSS, or ASP.NET ViewState compromise.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 9.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/99965",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.telerik.com/blogs/security-alert-for-telerik-ui-for-asp.net-ajax-and-progress-sitefinity",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "http://www.telerik.com/support/kb/aspnet-ajax/details/cryptographic-weakness",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://www.exploit-db.com/exploits/43873/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-9248",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2017-9248",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
