Summary Points
- Attackers exploited CVE-2019-18935 to execute remote code on unpatched Telerik UI servers.
- Post-exploitation activities included deploying reverse shells, attempting privilege escalation, and installing web shells.
- The vulnerability enables persistent remote access, increasing the risk of data breaches and server control.
Threat, Attack Techniques, and Targets
The AhnLab Security Intelligence Center (ASEC) has found two attack cases that exploited a remote code execution vulnerability. This vulnerability is identified as CVE-2019-18935. The attacks targeted servers using Telerik UI for ASP.NET AJAX that had not been patched. In the first case, the attacker used the vulnerability to run a reverse shell, try to gain higher privileges, and install a web shell. The second attack involved similar methods, including installing tools to scan and compromise the system further. These attacks mainly focus on servers using Telerik UI for ASP.NET AJAX that are not updated with security patches.
Impact, Security Implications, and Remediation Guidance
The attacks can cause serious damage. They allow hackers to run malicious code on the server. This can lead to data theft, system control, and further exploitation. Because hackers can install web shells, they may easily access the server later. They can also use scanning tools to find other vulnerabilities. For organizations, this means a higher risk of data leaks or system damage. To stay safe, it is very important to follow security updates and patch vulnerable software. If you want specific guidance on fixing this issue, it is best to consult the vendor or official security sources.
Expand Your Tech Knowledge
Explore the future of technology with our detailed insights on Artificial Intelligence.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
