---
schema: 1
kind: vulnerability
title: "CVE-2019-18935, Progress Telerik UI for ASP.NET AJAX: a patched-since-2020 deserialization RCE still exploited, now via an in-memory Godzilla web shell registered on ASP.NET's VirtualPathProvider"
headline: "AhnLab documents two fresh, unrelated intrusions still riding a six-year-old Telerik deserialization bug into unpatched IIS servers"
summary: >
  AhnLab ASEC reports two separate 2026 intrusions exploiting CVE-2019-18935, a .NET deserialization flaw in Telerik
  UI for ASP.NET AJAX's RadAsyncUpload feature, patched since version 2020.1.114 but still reachable on unpatched IIS
  deployments. One installs a file-less, memory-resident Godzilla-protocol web shell via ASP.NET's VirtualPathProvider
  extensibility point plus a web-shell-adapted SweetPotato privilege-escalation tool; the other drops only a
  Rust-based external reconnaissance scanner reporting hits over the Telegram Bot API.
discovered_at: "2026-09-28T04:04:46Z"
updated_at: null
event_date: "2026-09-27"
run_id: 2026-09-28T0404Z-intel
priority: notable
immediate_action: null
tags: [vulnerabilities, rce, pre-auth, patch-available]
regions: [global]
sectors: [public-sector, technology]
entities: [product:progress-telerik-ui-for-asp-net-ajax]
techniques: [T1190, T1505.003, T1134.001, T1595.002, T1102]
affected_products: ["Progress Telerik UI for ASP.NET AJAX"]
cves:
  - id: CVE-2019-18935
    cvss: null
    epss: null
    type: deserialization
    vector: zero-click
    auth: pre-auth
    status: [exploited, patch-available]
    affected: "Progress Telerik UI for ASP.NET AJAX before 2020.1.114"
    fixed: "2020.1.114"
sources:
  - url: "https://asec.ahnlab.com/en/95561/"
    publisher: "AhnLab ASEC"
    date: "2026-09-27"
    role: primary
closed_sources: []
evidence:
  - quote: "CVE-2019-18935 is a .NET deserialization vulnerability in RadAsyncUpload, a file upload feature; if exploited, a threat actor can perform remote code execution with the privileges of the w3wp.Exe process on an IIS web server."
    publisher: "AhnLab ASEC"
  - quote: "It then registers a malicious request-handling function with ASP.NET's VirtualPathProvider, enabling the web shell to run in the web server process's memory without requiring a separate .Aspx file."
    publisher: "AhnLab ASEC"
  - quote: "The scanner is a Rust-based tool that receives a list of targets from a remote server and asynchronously scans for URLs leading to WordPress installation and configuration pages."
    publisher: "AhnLab ASEC"
verification: single-source
sourcing_note: >
  AhnLab ASEC is the sole assessor; no corroborating outlet has yet reported on this same-day finding. ASEC's own
  page was unreachable on every transport at composition time, so this entry is composed from a verified verbatim
  capture of the primary rather than a fresh re-fetch; confidence is held at medium accordingly.
confidence: medium
references:
  - "2026-08-23/uat-10147-agentic-ai-exploitation-oob-confirmation"
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions: []
updates: []
migrated_from: null
---

AhnLab's ASEC documents two separate, unrelated 2026 intrusions in Korea that both exploit CVE-2019-18935, a .NET
deserialization vulnerability in the RadAsyncUpload file-upload feature of Telerik UI for ASP.NET AJAX, patched by
the vendor since version 2020.1.114 but still reachable on unpatched IIS deployments; successful exploitation
executes code with the privileges of the `w3wp.exe` worker-process account
([AhnLab ASEC, 2026-09-27](https://asec.ahnlab.com/en/95561/)). In the first case, the attacker used the flaw to
launch a reverse shell, ran basic reconnaissance, and deployed modified Potato-family token-impersonation tools,
including a web-shell-adapted build of SweetPotato, to escalate to SYSTEM. The intrusion culminated in a
memory-resident, file-less web shell: a payload DLL locates the IIS worker thread that has already loaded
`Telerik.Web.UI`, loads an embedded module into that process's memory, and registers a malicious request handler
directly with ASP.NET's VirtualPathProvider extensibility point, so the web shell runs entirely in server memory
with no `.aspx` file ever written to disk ([AhnLab ASEC, 2026-09-27](https://asec.ahnlab.com/en/95561/)). The
installed shell follows the Godzilla web-shell protocol: it distinguishes actions via an HTTP request's `Type`
header, decrypts the request body, caches an attacker-supplied .NET payload in a cookie-bound session on first
contact, and re-invokes that cached payload on each later request: an arbitrary, extensible in-memory .NET
execution primitive that leaves minimal on-disk forensic trace.

The second, unrelated intrusion used the same CVE purely to launch a Rust-based reconnaissance scanner: it pulls a
target list from an operator-controlled server, asynchronously probes each target across candidate URL paths for
exposed WordPress installer/configuration pages, and reports any hit back to the operator over the Telegram Bot API,
without dropping a reverse shell or web shell on the compromised Telerik host itself
([AhnLab ASEC, 2026-09-27](https://asec.ahnlab.com/en/95561/)). ASEC notes this CVE has a long exploitation history:
Blue Mockingbird's 2020 Monero-mining campaign, and a 2023 CISA/FBI/MS-ISAC advisory covering US federal-agency IIS
servers, underscoring that a legacy, patched-since-2020 vulnerability in a still-deployed enterprise .NET web
component remains a live, low-cost initial-access vector six years after disclosure.

**Detection and hunting.** In process-creation telemetry, alert on `w3wp.exe` spawning `cmd.exe` or PowerShell with
no corresponding legitimate application feature to explain it; the VirtualPathProvider registration technique means
no new `.aspx` file appears on disk, so file-integrity monitoring over the web root will miss this shell entirely;
in-memory module-loading detection (unusual modules loaded into the IIS worker process, or EDR visibility into
.NET AppDomain assembly loads) is the telemetry class that catches it. The Godzilla protocol's own signature is a
request carrying a non-standard `Type` header to an otherwise ordinary-looking Telerik endpoint. For the second
intrusion, look for outbound connections from an IIS host to `api.telegram.org`, a pattern with no legitimate
counterpart on a production Telerik/IIS server.

**Triage:** SweetPotato and other Potato-family tools are dual-use privilege-escalation utilities also used in
authorized red-team engagements, so the discriminator is context: their invocation from a web-shell process rather
than an interactive administrative session, and their appearance immediately following exploitation of an unpatched
RadAsyncUpload endpoint rather than a scheduled maintenance task.

**Defender takeaway:** patch to 2020.1.114 or later now; where patching must wait, restrict or disable the
RadAsyncUpload handler and monitor for the VirtualPathProvider-registration pattern described above. A vulnerability
whose patch has existed for six years is not lower priority than a fresh disclosure when active exploitation is
confirmed; the normal patch cadence has already had years to close this gap on any server still running it.
