01 · Reported
asec.ahnlab.com publishes. The report enters the corpus as TL-2026-2726, rated critical.
CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS Servers
- nvd.nist.gov
- cisa.gov
- redcanary.com
- bishopfox.com
- github.com
- threatprotect.qualys.com
02 · Enriched
Two CVEs, CVSS 9.8, CWE-502. On CISA’s KEV list since Nov 2021.
- CVE-2019-18935
- CVE-2017-11317
- CWE-502
- AV
- N
- AC
- L
- PR
- N
- UI
- N
- S
- U
- C
- H
- I
- H
- A
- H
Fixed in 2020.1.114 (R1 2020) and laterOn CISA KEV since 3 Nov 2021
6.9 years from CVE reservation to this campaign
03 · Mapped
Sixteen ATT&CK techniques across nine of the fifteen Enterprise tactics.
- 1
- 1
- 2
- 1
- 1
- 2
- 3
- 4
- 1
16 techniques across 9 of 15 Enterprise tactics
- T1595.002
- T1190
- T1059.003
- T1505.003
- T1134.001
- T1620
- T1082
- T1033
- T1057
- T1071.001
- +6
04 · Detected
Nine rules: 3 Splunk SPL, 3 Microsoft KQL, 3 Sigma.
- DeviceProcessEvents
- W3CIISLog
- windows_security
- DeviceEvents
- DeviceNetworkEvents
- sysmon
- network_connection
- iis_w3c_logs
- +4
Query text · withheldunlocks with a free account
05 · Ready to deploy
Every rule names its data sources, false positives and tuning notes. A free account unlocks the query text.
Splunk SPLTL-2026-2726-SPL-001Critical severity · high confidence
Splunk SPLTL-2026-2726-SPL-001Critical severity · high confidence
Telerik RadAsyncUpload CVE-2019-18935 Deserialization Exploit + w3wp.exe Command Shell
Detects HTTP requests to the Telerik UI RadAsyncUpload handler / Telerik.Web.UI.WebResource.axd endpoint carrying an encrypted rauPostData parameter (the CVE-2017-11317/CVE-2019-18935 exploit chain against RadAsyncUpload's AssemblyInstaller deserialization gadget), correlated with the IIS worker process w3wp.exe spawning cmd.exe shortly afterward — the observable signature of successful remote code execution in the AhnLab ASEC-documented attack cases.
Data sources
- iis_w3c_logs
- sysmon
- windows_security
ATT&CK
- T1190
- T1059.003
- T1620
False positives Custom ASP.NET diagnostic or health-check pages that legitimately invoke rauPostData-style upload handlers or shell out from w3wp.exe for approved administrative tooling
Tuning Baseline legitimate RadAsyncUpload usage on patched (2020.1.114+) hosts first; scope the w3wp.exe->cmd.exe join to a 5-minute correlation window and exclude known application-pool identities that run inventoried maintenance scripts.
Create a free accountUnlocks SPL, KQL and Sigma text for every threat. No card needed.