Telerik is a software development company that offers various tools and components for building web applications. In 2019, a vulnerability was discovered in Telerik’s UI for ASP.NET AJAX component that allowed remote code execution. The vulnerability affected versions of the software released between 2007 and 2018 and could be exploited by attackers to take control of affected systems.
Microsoft released a patch for the vulnerability in October 2019, but many organizations may still be at risk if they have not applied the patch or are running outdated versions of the software. It is important for organizations to keep their software up-to-date with the latest security patches and to regularly scan their systems for vulnerabilities.
Additionally, it is recommended to implement multi-factor authentication, use strong passwords, and limit user privileges to reduce the risk of successful attacks. Cyber security awareness training for employees can also help prevent social engineering attacks that may exploit vulnerabilities such as the Telerik vulnerability. Employees should be trained on how to identify and report suspicious activity to help prevent successful attacks.