Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Unsafe Reflection in Progress Telerik UI for AJAX

IdentifiersCVE-2025-3600CWE-470· Use of Externally-Controlled Input…

CVE-2025-3600 is an unsafe reflection vulnerability in Progress Telerik UI for AJAX / ASP.NET AJAX affecting versions 2011.2.712 through 2025.1.218. The vulnerable code path is reachable via the Telerik handler endpoint /Telerik.Web.UI.WebResource.axd with type=iec. In the ImageEditorCacheHandler flow, when dkey=1 is supplied, the prtype query parameter is passed through RadImageEditor.GetICacheImageProviderType into Type.GetType, and the resolved type is then instantiated via Activator.CreateInstance in RadImageEditor.InitCacheImageProvider before being cast to ICacheImageProvider. This allows attacker-controlled selection and instantiation of available .NET types with public parameterless constructors. Progress described the issue as leading to an unhandled exception and denial of service, and public research demonstrated a reliable crash gadget on .NET Framework using System.Management.Automation.Remoting.WSManPluginManagedEntryInstanceWrapper, whose finalizer can trigger an unhandled exception when freeing an uninitialized handle. Public research further indicates that, depending on the target application's available classes, assembly resolution behavior, and surrounding application logic, the same primitive may be usable for higher-impact exploitation including remote code execution.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

The baseline impact is denial of service through crash of the hosting web process or application pool recycle caused by instantiation of a type whose constructor/finalizer leads to an unhandled exception. In environments with suitable gadget types, unsafe constructors, or exploitable assembly resolution behavior, exploitation may extend beyond DoS and enable remote code execution. Public research demonstrated that impact can depend heavily on the targeted environment and application-specific classes present on the server.

Mitigation

If you can’t patch tonight, do this now.

If immediate patching is not possible, reduce exposure to the Telerik handler endpoint /Telerik.Web.UI.WebResource.axd, especially requests using type=iec and attacker-controlled prtype values. Restrict external access to affected applications, place them behind authentication or network access controls where feasible, and monitor/block suspicious requests targeting the ImageEditorCacheHandler path and parameters. Because public research indicates environment-dependent paths to RCE, mitigation should assume risk beyond simple availability loss until patching is completed.

Remediation

Patch, then assume compromise.

Upgrade Progress Telerik UI for AJAX to a fixed version. The provided content states the issue was addressed by Progress on April 30, 2025, and that a patch was released in version 2025.1.416. Affected versions are reported as 2011.2.712 through 2025.1.218. Apply the vendor fix across all applications bundling Telerik UI for AJAX, including third-party products that embed the component.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Progress SoftwareTelerik Ui For Asp.Net Ajaxapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

ACTIVITY FEED

Recent activity

28 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity22

Community discussion across Reddit, Mastodon, and other social sources.