CRITICAL
CVE-2021-23758
CVSS
9.8
KEV
Description
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
Weakness (CWE)
CWE-502
Deserialization of Untrusted Data
EPSS Score
82.58%
Probability of exploitation in next 30 days
99.7th percentile
References
http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.html
Exploit, VDB Entry
https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57
Patch, Third Party Advisory
https://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971
Third Party Advisory
https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23758
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.