A remote code execution flaw in Telerik UI for ASP.NET AJAX that was fixed years ago is still giving attackers a way into Windows web servers. The AhnLab Security intelligence Center (ASEC) has documented two fresh attack cases in South Korea in which intruders exploited CVE-2019-18935 on unpatched Microsoft IIS servers, then used the foothold to plant a memory-resident web shell in one case and to launch a scanner hunting for exposed WordPress sites in the other.
The bug is not obscure. It carries a CVSS score of 9.8, and CISA added it to its Known Exploited Vulnerabilities catalog in November 2021, where it is marked as known to be used in ransomware campaigns. ASEC notes that Red Canary tied it to the Blue Mockingbird cryptomining operation in 2020, and that a 2023 CISA, FBI and MS-ISAC advisory reported it among the flaws used against IIS servers at US federal agencies. What ASEC adds is that servers running old Telerik builds are still out there, and attackers are still finding them.
A file upload feature that runs attacker code
Telerik UI for ASP.NET AJAX is a set of interface components developers use to build ASP.NET web applications. According to ASEC, CVE-2019-18935 is a .NET deserialization flaw in RadAsyncUpload, the product's file upload feature. Deserialization is the server rebuilding an object from data it receives, and when that data is attacker-controlled it can be abused to run code. Here the code runs with the privileges of w3wp.exe, the IIS worker process that hosts the web application.
Case one ended in a web shell that lives in memory
In the first case, the exploit launched a reverse shell, a connection from the victim server back to the attacker at 206[.]82[.]6[.]22 on port 80 that hands over a cmd.exe prompt. The attacker queried the host name, privileges and running processes, then tried to escalate to SYSTEM with several modified Potato-family tools, including a SweetPotato variant adapted for use from a web shell. ASEC says these tools rely on token spoofing techniques such as PrintSpoofer.
The final payload was a Godzilla-style web shell with no .aspx file on disk. The loader looks for an environment where Telerik.Web.UI is loaded, pulls an embedded godmemshell.dll into memory and registers a malicious request handler with ASP.NET's VirtualPathProvider, so the shell answers from inside the web server's own process. It decrypts incoming requests, stores the .NET payload it receives on the first request in a cookie-based session, calls it again on later requests and returns the results encrypted. Memory-only shells like this leave little for a file scan to find, a pattern also seen in a recent F5 BIG-IP intrusion.
Case two turned the server into a WordPress hunter
The second attacker skipped the shell entirely. The exploit payload contained only a command to run a scanner, a Rust tool that fetches a target list from a remote server and asynchronously probes 53 common paths, such as /wp, /old, /backup and /blog, for WordPress installation and configuration pages. When a path exposes /wp-admin/setup-config.php or /wp-admin/install.php, the tool reports the URL and the server's public IP address to a Telegram bot in an attachment named red.txt.
Upgrade Telerik UI to 2020.1.114 or later
ASEC's advice is to upgrade Telerik UI for ASP.NET AJAX to version 2020.1.114 or later, and to the latest release where possible. Defenders should also:
- check C:\Users\Public\ and C:\Users\Public\Documents\ for dropped files;
- look for cmd.exe, powershell.exe or similar processes spawned by w3wp.exe;
- restrict access to WordPress setup-config.php and install.php pages that have no reason to be exposed.
Indicators of compromise
- MD5: 0a4be0b6c650ffdcd1c22db56f1c4aec, 10f705728d228ad949b7894c1a85a2b1, 177e34d9174766a1d187a0c82de4c02f, 18fb4e070653fc9791e0e408d8cb1c8e, 1dbfda02d74b6a7586c4430175204c28
- Reverse shell C2: 206[.]82[.]6[.]22:80
- Scanner target list: hxxp://65[.]98[.]5[.]158:31337/ins[.]txt
- Other URLs listed by ASEC: hxxp://2[.]59[.]133[.]147:31338/ins[.]txt, hxxp://2[.]59[.]133[.]147:31338/sm[.]json, hxxp://45[.]138[.]16[.]187:31337/bb[.]json, hxxp://45[.]138[.]16[.]187:31337/cofuz[.]json
ASEC did not attribute either case to a named group, and the two intrusions used different tooling. The common thread is the entry point. A flaw that has sat on CISA's exploited list for nearly five years is no longer a zero-day problem, it is an inventory problem, and every forgotten Telerik build is still being tested by somebody.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.