CVE-2021-23758
HIGHAll versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
Published: 12/3/2021Modified: 8/27/2026
Related Intelligence (0)
No articles currently reference this CVE.
References (8)
http://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.htmlExploitVDB Entryhttps://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57PatchThird Party Advisoryhttps://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971Third Party Advisoryhttp://packetstormsecurity.com/files/175677/AjaxPro-Deserialization-Remote-Code-Execution.htmlExploitVDB Entryhttps://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57PatchThird Party Advisoryhttps://snyk.io/vuln/SNYK-DOTNET-AJAXPRO2-1925971Third Party Advisoryhttps://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/ExploitThird Party Advisoryhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23758US Government Resource