Sceawere
Vulnerability Detail
CVE-2026-77805UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Telerik Fiddler Classic Insecure Signature Validation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.9
- Creation Date
- 6h ago
- Vendor
- Progress Software
- Product
- Progress® Telerik® Fiddler® Classic
- Attack Type
- CWE-347: Improper Verification of Cryptographic Signature
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose certificate subject name matches a broad allow list of publisher name fragments, rather than verifying that the file is the specific executable shipped with that version of the product. A local threat actor with low privileges who replaces one of these helper executables with any other validly signed binary from an allow-listed publisher can cause the substituted binary to be executed by the application, including with Administrator privileges for the tools that request elevation, resulting in privilege escalation and execution of unintended code. Successful exploitation requires the user to launch the affected external tool and to approve the elevation prompt without noticing that it refers to a different executable.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.9",
"pubDate": "2026-10-05T13:16:54.740Z",
"pubdate": "2026-10-05T13:16:54.740Z",
"executiveSummary": "This vulnerability involves insufficient integrity validation of external helper tools in In Progress Telerik Fiddler Classic for Windows, affecting versions prior to v6.0.20262.10021.\nThe application relies on Authenticode signature checks against a broad allow list of publisher name fragments rather than verifying the cryptographic hash of specific, authorized executables.\nThis flaw allows a local attacker with low-privileged access to perform arbitrary code execution by replacing a legitimate helper binary with a malicious file that is signed by any certificate matching the publisher allow list.\nIf the replaced helper tool requires elevation, the application may execute the malicious binary with Administrator privileges, leading to local privilege escalation.\nSuccessful exploitation requires the attacker to replace the helper binary on the file system and social engineer or entice a user to launch the tool and approve the UAC elevation prompt.",
"technicalDetails": "The root cause of this vulnerability lies in an overly permissive validation logic implemented within Telerik Fiddler Classic when invoking auxiliary helper executables. The application’s security mechanism performs an Authenticode verification of the target binary; however, it fails to enforce a strict cryptographic identity check.\nInstead of verifying that the binary matches the specific file hash (SHA-256) of the authorized component shipped with the product, the application only validates that the binary possesses a valid digital signature issued by a certificate whose Subject Name field contains specific publisher name fragments. This approach is conceptually flawed as it trusts any binary provided that the signer matches a broader category rather than the specific software vendor’s intent.\nAn attacker with local access can replace the legitimate helper executable with a malicious binary that is also signed by a publisher matching the allow list criteria. Many commercial or enterprise software vendors may share similar publisher name segments in their certificates, or an attacker may possess an unrelated certificate that meets the loose validation criteria.\nThe attack flow proceeds as follows: 1) The attacker identifies a target helper binary invoked by Fiddler Classic. 2) The attacker overwrites or swaps this file with a malicious executable that carries a signature acceptable to the Fiddler validation routine. 3) The attacker triggers the functionality in Fiddler Classic that invokes the helper tool. 4) If the tool requires elevated privileges, the system displays a User Account Control (UAC) prompt to the user. 5) The user, misled by the context of the application's intended functionality, approves the prompt. 6) The operating system executes the malicious binary with the requested (Administrator) privileges, resulting in full compromise of the user context or system depending on the requested elevation level.\nThe vulnerability is primarily a privilege escalation primitive triggered by the misuse of digital signature trust. It does not require network exposure, as the attack is constrained to local file system manipulation and user-interaction-dependent execution within the host environment."
}