Zetlyn

Ajax.NET Professional Deserialization of Untrusted Data Vulnerability

cve CVE-2021-23758 2 sources, 2 claims · Watch

CISA Known Exploited Vulnerabilities writes:
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requir… the claim

What each source says

PropertySourceSaidMeans here
Cwes
cwes
CISA Known Exploited VulnerabilitiesCWE-502
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
CWE-502
Read by
field:cwes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2021-23758",
  "cwes": "CWE-502",
  "dateAdded": "2026-08-26",
  "dueDate": "2026-09-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758",
  "product": "Ajax.NET Professional",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Ajax.NET Professional",
  "vulnerabilityName": "Ajax.NET Professional Deserialization of Untrusted Data Vulnerability"
}
—
Due date
due_date
CISA Known Exploited Vulnerabilities2026-09-09
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
2026-09-09
Read by
field:dueDate
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2021-23758",
  "cwes": "CWE-502",
  "dateAdded": "2026-08-26",
  "dueDate": "2026-09-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758",
  "product": "Ajax.NET Professional",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Ajax.NET Professional",
  "vulnerabilityName": "Ajax.NET Professional Deserialization of Untrusted Data Vulnerability"
}
—
Exploited
exploited
CISA Known Exploited Vulnerabilitiesyes
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
yes
Read by
const:yes
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2021-23758",
  "cwes": "CWE-502",
  "dateAdded": "2026-08-26",
  "dueDate": "2026-09-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758",
  "product": "Ajax.NET Professional",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Ajax.NET Professional",
  "vulnerabilityName": "Ajax.NET Professional Deserialization of Untrusted Data Vulnerability"
}
—
Forensic triage
forensic_triage
CISA Known Exploited Vulnerabilitiesfalse
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
No
Read by
field:forensicTriage
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2021-23758",
  "cwes": "CWE-502",
  "dateAdded": "2026-08-26",
  "dueDate": "2026-09-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758",
  "product": "Ajax.NET Professional",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Ajax.NET Professional",
  "vulnerabilityName": "Ajax.NET Professional Deserialization of Untrusted Data Vulnerability"
}
—
Known ransomware campaign use
known_ransomware_campaign_use
CISA Known Exploited VulnerabilitiesUnknown
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Unknown
Read by
field:knownRansomwareCampaignUse
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2021-23758",
  "cwes": "CWE-502",
  "dateAdded": "2026-08-26",
  "dueDate": "2026-09-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758",
  "product": "Ajax.NET Professional",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Ajax.NET Professional",
  "vulnerabilityName": "Ajax.NET Professional Deserialization of Untrusted Data Vulnerability"
}
—
Platform
platform
Metasploit exploit modulesWindows
receipt
Source
Metasploit exploit modules
Its words
Windows
Read by
field:platform
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 12:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd, x86, x64",
  "author": [
    "Hans-Martin Münch (MOGWAI LABS)",
    "Jemmy Wang"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module leverages an insecure deserialization of data to get\n          remote code execution on the target OS in the context of the user\n          running the website which utilized AjaxPro.\n\n          To achieve code execution, the module will construct some JSON data\n          which will be sent to the target. This data will be deserialized by\n          the AjaxPro JsonDeserializer and will trigger the execution of the\n          payload.\n\n          All AjaxPro versions prior to 21.10.30.1 are vulnerable to this\n          issue, and a vulnerable method which can be used to trigger the\n          deserialization exists in the default AjaxPro namespace.\n\n          AjaxPro 21.10.30.1 removed the vulnerable method, but if a custom\n          method that accepts a parameter of type that is assignable from\n          `ObjectDataProvider` (e.g. `object`) exists, the vulnerability can\n          still be exploited.\n\n          This module has been tested successfully against official AjaxPro on\n          version 7.7.31.1 without any modification, and on version 21.10.30.1\n          with a custom vulnerable method added.",
  "disclosure_date": "2021-12-03",
  "fullname": "exploit/windows/http/ajaxpro_deserialization_rce",
  "is_install_path": true,
  "mod_time": "2025-12-17 16:12:31 +0000",
  "name": "AjaxPro Deserialization Remote Code Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "screen-effects",
      "ioc-in-logs",
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/windows/http/ajaxpro_deserialization_rce.rb",
  "platform": "Windows",
  "post_auth": false,
  "rank": 600,
  "ref_name": "windows/http/ajaxpro_deserialization_rce",
  "references": [
    "CVE-2021-23758",
    "URL-https://mogwailabs.de/en/blog/2022/01/vulnerability-spotlight-rce-in-ajax.net-professional/"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Windows Command",
    "Windows Dropper"
  ],
  "type": "exploit"
}
—
Product
product
CISA Known Exploited VulnerabilitiesAjax.NET Professional
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Ajax.NET Professional
Read by
field:product
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2021-23758",
  "cwes": "CWE-502",
  "dateAdded": "2026-08-26",
  "dueDate": "2026-09-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758",
  "product": "Ajax.NET Professional",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Ajax.NET Professional",
  "vulnerabilityName": "Ajax.NET Professional Deserialization of Untrusted Data Vulnerability"
}
—
Rank
rank
Metasploit exploit modules600
Excellent. Cannot crash the service. A memory-corruption exploit does not qualify.
receipt
Source
Metasploit exploit modules
Its words
600
Read by
field:rank
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 12:59 UTC
Original
open at the source
What the source handed over
{
  "aliases": [],
  "arch": "cmd, x86, x64",
  "author": [
    "Hans-Martin Münch (MOGWAI LABS)",
    "Jemmy Wang"
  ],
  "autofilter_ports": [
    80,
    8080,
    443,
    8000,
    8888,
    8880,
    8008,
    3000,
    8443
  ],
  "autofilter_services": [
    "http",
    "https"
  ],
  "check": true,
  "default_credential": false,
  "description": "This module leverages an insecure deserialization of data to get\n          remote code execution on the target OS in the context of the user\n          running the website which utilized AjaxPro.\n\n          To achieve code execution, the module will construct some JSON data\n          which will be sent to the target. This data will be deserialized by\n          the AjaxPro JsonDeserializer and will trigger the execution of the\n          payload.\n\n          All AjaxPro versions prior to 21.10.30.1 are vulnerable to this\n          issue, and a vulnerable method which can be used to trigger the\n          deserialization exists in the default AjaxPro namespace.\n\n          AjaxPro 21.10.30.1 removed the vulnerable method, but if a custom\n          method that accepts a parameter of type that is assignable from\n          `ObjectDataProvider` (e.g. `object`) exists, the vulnerability can\n          still be exploited.\n\n          This module has been tested successfully against official AjaxPro on\n          version 7.7.31.1 without any modification, and on version 21.10.30.1\n          with a custom vulnerable method added.",
  "disclosure_date": "2021-12-03",
  "fullname": "exploit/windows/http/ajaxpro_deserialization_rce",
  "is_install_path": true,
  "mod_time": "2025-12-17 16:12:31 +0000",
  "name": "AjaxPro Deserialization Remote Code Execution",
  "needs_cleanup": null,
  "notes": {
    "Reliability": [
      "repeatable-session"
    ],
    "SideEffects": [
      "screen-effects",
      "ioc-in-logs",
      "artifacts-on-disk"
    ],
    "Stability": [
      "crash-safe"
    ]
  },
  "path": "/modules/exploits/windows/http/ajaxpro_deserialization_rce.rb",
  "platform": "Windows",
  "post_auth": false,
  "rank": 600,
  "ref_name": "windows/http/ajaxpro_deserialization_rce",
  "references": [
    "CVE-2021-23758",
    "URL-https://mogwailabs.de/en/blog/2022/01/vulnerability-spotlight-rce-in-ajax.net-professional/"
  ],
  "rport": 80,
  "session_types": false,
  "targets": [
    "Windows Command",
    "Windows Dropper"
  ],
  "type": "exploit"
}
—
Vendor project
vendor_project
CISA Known Exploited VulnerabilitiesAjax.NET Professional
receipt
Source
CISA Known Exploited Vulnerabilities
Its words
Ajax.NET Professional
Read by
field:vendorProject
Said since
2026-09-28 11:44 UTC
Last answered
2026-10-02 13:00 UTC
What the source handed over
{
  "cveID": "CVE-2021-23758",
  "cwes": "CWE-502",
  "dateAdded": "2026-08-26",
  "dueDate": "2026-09-09",
  "forensicTriage": "No",
  "knownRansomwareCampaignUse": "Unknown",
  "notes": "This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/michaelschwarz/Ajax.NET-Professional/commit/b0e63be5f0bb20dfce507cb8a1a9568f6e73de57 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-23758",
  "product": "Ajax.NET Professional",
  "requiredAction": "Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.",
  "shortDescription": "Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.",
  "vendorProject": "Ajax.NET Professional",
  "vulnerabilityName": "Ajax.NET Professional Deserialization of Untrusted Data Vulnerability"
}
—

vulnerability

Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
zetlyn/cve-kev · 2026-08-26
cwes CWE-502 due_date 2026-09-09 exploited yes forensic_triage false known_ransomware_campaign_use Unknown product Ajax.NET Professional vendor_project Ajax.NET Professional

exploit

AjaxPro Deserialization Remote Code Execution
zetlyn/cve-metasploit · 2021-12-03
platform Windows rank 600 source