2026-09-28NOTABLEexploitedAhnLab documents two attack cases still riding a six-year-old Telerik deserialization bug into unpatched IIS servers
Telerik UI for ASP.NET AJAX deserialization RCE (RadAsyncUpload), patched since 2020.1.114, actively exploited via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider (AhnLab ASEC, 2026-09-27); background-referenced by the 2026-08-23 UAT-10147 entry
cve · CVE-2019-18935 single-source
Coverage
1
first 2026-08-23 → last 2026-10-07
Latest activity
2026-09-28
AhnLab documents two attack cases still riding a six-year-old Telerik deserialization bug into unpatched IIS…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, technology
Sources cited
2
2 hosts
Defender insights
What each entry about CVE-2019-18935 tells a defender to do, newest first.
Triage · detection
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (5 across 6 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- ReconnaissanceActive Scanning: Vulnerability Scanning
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell
- Privilege EscalationAccess Token Manipulation: Token Impersonation/Theft
- StealthAccess Token Manipulation: Token Impersonation/Theft
- Command and ControlWeb Service
Reconnaissance TA0043
T1595.002Active Scanning: Vulnerability Scanning×1
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially aligns with the target of a specific exploit the adversary may seek to use.
Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗
Privilege Escalation TA0004
T1134.001Access Token Manipulation: Token Impersonation/Theft×1
Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.
Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗
Stealth TA0005
T1134.001Access Token Manipulation: Token Impersonation/Theft×1
Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For example, an adversary can duplicate an existing token using `DuplicateToken` or `DuplicateTokenEx`. The token can then be used with `ImpersonateLoggedOnUser` to allow the calling thread to impersonate a logged on user's security context, or with `SetThreadToken` to assign the impersonated token to a thread.
Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗
Command and Control TA0011
T1102Web Service×1
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites, cloud services, and social media acting as a mechanism for C2 may give a significant amount of cover due to the likelihood that hosts within a network are already communicating with them prior to a compromise. Using common services, such as those offered by Google, Microsoft, or Twitter, makes it easier for adversaries to hide in expected noise. Web service providers commonly use SSL/TLS encryption, giving adversaries an added level of protection.
Evidence: 2026-09-28/cve-2019-18935-telerik-godzilla-webshell-virtualpathprovider · ATT&CK page ↗
Entries about Telerik UI for ASP.NET AJAX deserialization RCE (RadAsyncUpload), patched since 2020.1.114, actively exploited via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider (AhnLab ASEC, 2026-09-27); background-referenced by the 2026-08-23 UAT-10147 entry (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- asec.ahnlab.com1 (50%)
- cisa.gov1 (50%)