CVE-2021-23758
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional Deserialization of Untrusted Data Vulnerability
Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
Code execution on enterprise application
Derived analysis: these labels are inferred from the source title, product, and summary. They are not vendor, CVE, CISA, or FIRST classifications.
Establish the exact reachable primitive and its preconditions. Use a harmless marker if authorized, preserve a clean control, and stop before persistence, secret access, or lateral movement.
Keep the signals separate
Confirm the product before the behavior.
- Match the exact product, build, deployment mode, and exposed component.
- Read the vendor advisory and current program policy.
- Choose one non-destructive discriminator with an explicit negative control.
- Stop at the first sufficient proof. A CVE match is context, not permission.
Dates and provenance
- CVE published
- 2021-12-03
- CVE modified
- 2026-08-27
- KEV date added
- 2026-08-26
- Dataset fetched
- 2026-08-27T13:17:14.532Z
Original records
- https://www.cve.org/CVERecord?id=CVE-2021-23758 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2021-23758 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23758 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.