CVE-2021-23758
KEV
🔴 Łataj teraz
Deserializacja niezaufanych danych w ajaxpro.2 umożliwia zdalne wykonanie kodu.
CVSS
8.1
EPSS
83.6%
Exploit
weaponized
Vendor
ajaxpro.2_project
Opis źródłowy (NVD)
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
deserialization exploit rce
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 83.6% |
| Opublikowano (NVD) | 2021-12-03 20:15:07 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-27 04:16:38 UTC |
Referencje
- http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html (report@snyk.io) [Exploit, VDB Entry]
- https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 (report@snyk.io) [Patch, Third Party Advisory]
- https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971 (report@snyk.io) [Third Party Advisory]
- https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/ (134c704f-9b21-4f2e-91b3-4a467353bcc0) [Exploit, Third Party Advisory]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23758 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]