← Back to overview

CVE-2021-23758 affects Ajax.NET Professional (AjaxPro), an open-source .NET library, which contains a deserialization of untrusted data vulnerability. This flaw allows attackers to exploit arbitrary .NET class deserialization, potentially leading to remote code execution. The vulnerability is catalogued in CISA's Known Exploited Vulnerabilities catalog under BOD 26-04. The affected product may be end-of-life or end-of-service, and users are advised to discontinue use or migrate to a supported alternative. A patch commit is available on GitHub for reference. The issue stems from improper handling of untrusted data during deserialization, a common and critical vulnerability class in web frameworks. Organizations using AjaxPro in their web applications are at risk of full system compromise if exploited. CISA has flagged this for prioritized remediation under its binding operational directive.

Affected products

  • Ajax.NET Professional (AjaxPro)

Related CVE's

  • CVE-2021-23758

Categories

  • Supply Chain & Dependencies
  • Web Technologies
  • Zero-Day Vulnerabilities