Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2021-23758: Ajax.NET Professional Ajax.NET Professional

Ajax.NET專業(AjaxPro)包含了對不可信資料脆弱性的去序列化,可以透過任意的.NET類進行遠端程式碼執行。受影響的產品(產品)可能是終身(EoL)和/或終身(EoS)。建議使用者停止使用和/或向支援的版本過渡。

CISA (English)

Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

廠商
Ajax.NET Professional
產品
Ajax.NET Professional
漏洞
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
加入日期
2026年8月26日
CISA 修補期限(美國聯邦機關)
2026年9月9日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-502

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02