Sceawere

Vulnerability Detail

CVE-2026-77805UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Telerik Fiddler Classic Insecure Signature Validation

Vulnerability Metadata

Severity
High
Score / CVSS
7.9
Creation Date
6h ago
Vendor
Progress Software
Product
Progress® Telerik® Fiddler® Classic
Attack Type
CWE-347: Improper Verification of Cryptographic Signature
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose certificate subject name matches a broad allow list of publisher name fragments, rather than verifying that the file is the specific executable shipped with that version of the product. A local threat actor with low privileges who replaces one of these helper executables with any other validly signed binary from an allow-listed publisher can cause the substituted binary to be executed by the application, including with Administrator privileges for the tools that request elevation, resulting in privilege escalation and execution of unintended code. Successful exploitation requires the user to launch the affected external tool and to approve the elevation prompt without noticing that it refers to a different executable.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.9",
  "pubDate": "2026-10-05T13:16:54.740Z",
  "pubdate": "2026-10-05T13:16:54.740Z",
  "executiveSummary": "This vulnerability involves insufficient integrity validation of external helper tools in In Progress Telerik Fiddler Classic for Windows, affecting versions prior to v6.0.20262.10021.\nThe application relies on Authenticode signature checks against a broad allow list of publisher name fragments rather than verifying the cryptographic hash of specific, authorized executables.\nThis flaw allows a local attacker with low-privileged access to perform arbitrary code execution by replacing a legitimate helper binary with a malicious file that is signed by any certificate matching the publisher allow list.\nIf the replaced helper tool requires elevation, the application may execute the malicious binary with Administrator privileges, leading to local privilege escalation.\nSuccessful exploitation requires the attacker to replace the helper binary on the file system and social engineer or entice a user to launch the tool and approve the UAC elevation prompt.",
  "technicalDetails": "The root cause of this vulnerability lies in an overly permissive validation logic implemented within Telerik Fiddler Classic when invoking auxiliary helper executables. The application’s security mechanism performs an Authenticode verification of the target binary; however, it fails to enforce a strict cryptographic identity check.\nInstead of verifying that the binary matches the specific file hash (SHA-256) of the authorized component shipped with the product, the application only validates that the binary possesses a valid digital signature issued by a certificate whose Subject Name field contains specific publisher name fragments. This approach is conceptually flawed as it trusts any binary provided that the signer matches a broader category rather than the specific software vendor’s intent.\nAn attacker with local access can replace the legitimate helper executable with a malicious binary that is also signed by a publisher matching the allow list criteria. Many commercial or enterprise software vendors may share similar publisher name segments in their certificates, or an attacker may possess an unrelated certificate that meets the loose validation criteria.\nThe attack flow proceeds as follows: 1) The attacker identifies a target helper binary invoked by Fiddler Classic. 2) The attacker overwrites or swaps this file with a malicious executable that carries a signature acceptable to the Fiddler validation routine. 3) The attacker triggers the functionality in Fiddler Classic that invokes the helper tool. 4) If the tool requires elevated privileges, the system displays a User Account Control (UAC) prompt to the user. 5) The user, misled by the context of the application's intended functionality, approves the prompt. 6) The operating system executes the malicious binary with the requested (Administrator) privileges, resulting in full compromise of the user context or system depending on the requested elevation level.\nThe vulnerability is primarily a privilege escalation primitive triggered by the misuse of digital signature trust. It does not require network exposure, as the attack is constrained to local file system manipulation and user-interaction-dependent execution within the host environment."
}
CVE-2026-77805: Telerik Fiddler Classic Insecure Signature Validation (HIGH Severity, CVSS: 7.9) | Sceawere