CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Telerik UI for ASP.NET AJAX deserialization RCE (RadAsyncUpload), patched since 2020.1.114, actively exploited via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider (AhnLab ASEC, 2026-09-27); background-referenced by the 2026-08-23 UAT-10147 entry

cve · CVE-2019-18935 single-source

Coverage
1
first 2026-08-23 → last 2026-10-07
Latest activity
2026-09-28
AhnLab documents two attack cases still riding a six-year-old Telerik deserialization bug into unpatched IIS…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, technology
Sources cited
2
2 hosts

Defender insights

What each entry about CVE-2019-18935 tells a defender to do, newest first.

2026-09-28NOTABLEexploitedAhnLab documents two attack cases still riding a six-year-old Telerik deserialization bug into unpatched IIS servers

Triage · detection

Story timeline

  1. 2026-09-28CVE-2019-18935, Progress Telerik UI for ASP.NET AJAX: a patched-since-2020 deserialization RCE still exploited, now via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider
    trending-vulnerabilitiesAhnLab documents two attack cases still riding a six-year-old Telerik deserialization bug into unpatched IIS servers
ATT&CK techniques (5 across 6 tactics)

5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • ReconnaissanceActive Scanning: Vulnerability Scanning
  • Initial AccessExploit Public-Facing Application
  • PersistenceServer Software Component: Web Shell
  • Privilege EscalationAccess Token Manipulation: Token Impersonation/Theft
  • StealthAccess Token Manipulation: Token Impersonation/Theft
  • Command and ControlWeb Service

Reconnaissance TA0043

T1595.002Active Scanning: Vulnerability Scanning×1

Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.

Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗

Initial Access TA0001

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗

Persistence TA0003

T1505.003Server Software Component: Web Shell×1

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗

Privilege Escalation TA0004

T1134.001Access Token Manipulation: Token Impersonation/Theft×1

Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.

Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗

Stealth TA0005

T1134.001Access Token Manipulation: Token Impersonation/Theft×1

Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.

Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗

Command and Control TA0011

T1102Web Service×1

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.

Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗

Entries about Telerik UI for ASP.NET AJAX deserialization RCE (RadAsyncUpload), patched since 2020.1.114, actively exploited via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider (AhnLab ASEC, 2026-09-27); background-referenced by the 2026-08-23 UAT-10147 entry (1)

2026-09-28 · view entry permalink →

NOTABLECVE-2019-18935exploitedupdatedNATOB2

CVE-2019-18935, Progress Telerik UI for ASP.NET AJAX: a patched-since-2020 deserialization RCE still exploited, now via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider

AhnLab's ASEC documents two separate attack cases in Korea that both exploit CVE-2019-18935, a .NET deserialization vulnerability in the RadAsyncUpload file-upload feature of Telerik UI for ASP.NET AJAX, patched by the vendor since version 2020.1.114 but still reachable on unpatched IIS deployments; successful exploitation executes code with the privileges of the w3wp.exe worker-process account (AhnLab ASEC, 2026-09-27). In the first case, the attacker used the flaw to launch a reverse shell, ran basic reconnaissance, and deployed modified Potato-family token-impersonation tools, including a web-shell-adapted build of SweetPotato, to escalate to SYSTEM. The intrusion culminated in a memory-resident, file-less web shell: a payload DLL locates the IIS worker thread that has already loaded Telerik.Web.UI, loads an embedded module into that process's memory, and registers a malicious request handler directly with ASP.NET's VirtualPathProvider extensibility point, so the web shell runs entirely in server memory with no .aspx file ever written to disk (AhnLab ASEC, 2026-09-27). The installed shell follows the Godzilla web-shell protocol: it distinguishes actions via an HTTP request's Type header, decrypts the request body, caches an attacker-supplied .NET payload in a cookie-bound session on first contact, and re-invokes that cached payload on each later request: an arbitrary, extensible in-memory .NET execution primitive that leaves minimal on-disk forensic trace.

The second case used the same CVE purely to launch a Rust-based reconnaissance scanner: it pulls a target list from an operator-controlled server, asynchronously probes each target across candidate URL paths for exposed WordPress installer/configuration pages, and reports any hit back to the operator over the Telegram Bot API, without dropping a reverse shell or web shell on the compromised Telerik host itself (AhnLab ASEC, 2026-09-27). ASEC notes this CVE has a long exploitation history: Blue Mockingbird's 2020 Monero-mining campaign, and a 2023 CISA/FBI/MS-ISAC advisory covering US federal-agency IIS servers, underscoring that a legacy, patched-since-2020 vulnerability in a still-deployed enterprise .NET web component remains a live, low-cost initial-access vector six years after disclosure.

Detection and hunting. In process-creation telemetry, alert on w3wp.exe spawning cmd.exe or PowerShell with no corresponding legitimate application feature to explain it; the VirtualPathProvider registration technique means no new .aspx file appears on disk, so file-integrity monitoring over the web root will miss this shell entirely; in-memory module-loading detection (unusual modules loaded into the IIS worker process, or EDR visibility into .NET AppDomain assembly loads) is the telemetry class that catches it. ASEC says the installed shell tells its actions apart by the request's Type header, so a request carrying that header to a Telerik endpoint is worth checking (AhnLab ASEC, 2026-09-27). For the second case, look for outbound connections from an IIS host to api.telegram.org, a pattern with no legitimate counterpart on a production Telerik/IIS server.

Triage: SweetPotato and other Potato-family tools are dual-use privilege-escalation utilities also used in authorized red-team engagements, so the discriminator is context: their invocation from a web-shell process rather than an interactive administrative session, and their appearance immediately following exploitation of an unpatched RadAsyncUpload endpoint rather than a scheduled maintenance task.

CVE-2019-18935 is a .NET deserialization vulnerability in RadAsyncUpload, a file upload feature; if exploited, a threat actor can perform remote code execution with the privileges of the w3wp.Exe process on an IIS web server.

It then registers a malicious request-handling function with ASP.NET's VirtualPathProvider, enabling the web shell to run in the web server process's memory without requiring a separate .Aspx file.

The scanner is a Rust-based tool that receives a list of targets from a remote server and asynchronously scans for URLs leading to WordPress installation and configuration pages.

AhnLab ASEC 2026-09-27

Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the server in the context of the w3wp.exe process.

CISA Known Exploited Vulnerabilities Catalog 2026-10-04
Correctionrun 2026-10-07T0404Z-intelheadlinesummarytagscvessourcesevidencesourcing_notebody

AhnLab's article of 2026-09-27 presents two separate attack cases in Korea and does not date the intrusions or call them unrelated; the wording above now follows it (AhnLab ASEC, 2026-09-27). ASEC says the first case's shell tells its actions apart by the request's Type header.

CISA's Known Exploited Vulnerabilities catalog has listed CVE-2019-18935 since 2021-11-03, and in catalog version 2026.10.04 its record marks the flaw as used in known ransomware campaigns; the catalog does not say when that flag was set (CISA KEV catalog, 2026-10-04). Because the CVE has been used in ransomware campaigns, a Telerik server where the web shell or the reconnaissance scanner turns up deserves a check for follow-on activity: assess what the w3wp.exe account and the SYSTEM-level escalation could reach, in addition to patching.

Builds on: Talos recovered the attacker's own generated tradecraft notes from an open directory, and the…

vulnerability28 Sep 04:04Zsingle-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • asec.ahnlab.com1 (50%)
  • cisa.gov1 (50%)