Sceawere
Vulnerability Detail
CVE-2026-77804UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Telerik Fiddler Classic TOCTOU Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.6
- Creation Date
- 6h ago
- Vendor
- Progress Software
- Product
- Progress® Telerik® Fiddler® Classic
- Attack Type
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a user-writable location and then launches the external TrustCert helper application, which elevates and imports the certificate from that file. A local threat actor with low privileges who replaces the temporary file between the time it is written and the time the elevated helper reads it can cause an attacker-supplied root certificate to be installed in the Local Computer Trusted Root Certification Authorities store, enabling subsequent interception and modification of TLS-protected traffic on the machine. Successful exploitation requires the user to initiate the certificate trust operation and approve the elevation prompt.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.6",
"pubDate": "2026-10-05T13:16:54.590Z",
"pubdate": "2026-10-05T13:16:54.590Z",
"executiveSummary": "This vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition within Telerik Fiddler Classic for Windows, specifically affecting the installation process of the HTTPS interception root certificate.\nThe flaw allows a local, low-privileged attacker to replace a temporary certificate file with a malicious root certificate before it is imported into the Local Computer Trusted Root Certification Authorities store.\nSuccessful exploitation enables an attacker to install an arbitrary root certificate, granting them the ability to intercept, decrypt, and modify TLS-protected traffic on the affected machine.\nThe vulnerability affects versions prior to 6.0.20262.10021. Exploitation is contingent upon the user initiating the certificate trust operation and granting the necessary administrative elevation via a UAC prompt.\nThis represents a significant security risk, as compromising the machine's trust store provides broad capabilities for man-in-the-middle (MitM) attacks.",
"technicalDetails": "The vulnerability arises from an insecure implementation of the certificate installation workflow in Telerik Fiddler Classic. During the HTTPS interception setup, the application generates a temporary file containing the root certificate and stores it in a directory accessible to local users.\nThe root cause is a TOCTOU race condition occurring between the write operation of the temporary file and the subsequent invocation of the 'TrustCert' helper application. The 'TrustCert' tool is designed to run with elevated privileges to perform the system-level installation into the Local Computer certificate store.\nThe attack flow follows a predictable sequence: First, a low-privileged attacker monitors the filesystem for the creation of the temporary certificate file during the Fiddler configuration process. Second, once the file is written but before the elevated 'TrustCert' application reads it, the attacker leverages a race condition to replace the legitimate file with a malicious, attacker-controlled certificate. Third, the user triggers the elevation prompt for the TrustCert utility. Finally, the utility, operating with high privileges, imports the malicious certificate into the trusted root store, effectively compromising the machine's certificate chain of trust.\nBecause the 'TrustCert' application trusts the file path provided to it without validating the integrity or provenance of the certificate file, it becomes a vector for privilege escalation and persistent machine-wide surveillance. The vulnerability requires local access and user interaction (triggering the trust process and approving the UAC elevation). Once the malicious certificate is installed, an attacker can silently intercept and manipulate all TLS/SSL traffic originating from or terminating on the victim's host, bypassing standard browser and application security controls that rely on the system's root certificate store.\nAffected versions include all iterations of Telerik Fiddler Classic for Windows released prior to v6.0.20262.10021. No specialized authentication is required, as the attacker operates within the context of a standard local user account."
}