AI analysis
Progress Telerik Fiddler Classic for Windows before version 6.0.20262.10021 does not adequately verify the integrity of external helper tools it launches. Before running a helper, it only checks that the file has a valid Authenticode signature whose certificate subject matches a broad allow list of publisher name fragments, instead of confirming it is the specific executable shipped with that product version. A local attacker with low privileges can replace a helper with any other validly signed binary from an allow-listed publisher so that, when a user starts the tool and approves the elevation prompt without noticing it names a different executable, the substitute runs—including as Administrator for tools that request elevation—yielding privilege escalation and unintended code execution. Windows users of affected Fiddler Classic builds are impacted. It is not listed in CISA KEV, and no public proof-of-concept is known.
What to do: Upgrade Progress Telerik Fiddler Classic for Windows to version 6.0.20262.10021 or later. Until then, do not approve unexpected UAC prompts from Fiddler helper tools, and check that helper executables under the Fiddler install directory have not been replaced by other signed binaries.
Affected
| Progress Software Telerik Fiddler Classic for Windows | versions prior to 6.0.20262.10021 |
Estimated exposure
largeon the order of hundreds of thousands of Windows developer installs (possibly low millions historically) — Fiddler Classic is a long-standing free Windows web-debugging proxy widely used by developers and testers; there is no published active-install or internet-scan count, so this is an order-of-magnitude estimate from that deployment pattern…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a valid Authenticode signature whose certificate subject name matches a broad allow list of publisher name fragments, rather than verifying that the file is the specific executable shipped with that version of the product. A local threat actor with low privileges who replaces one of these helper executables with any other validly signed binary from an allow-listed publisher can cause the substituted binary to be executed by the application, including with Administrator privileges for the tools that request elevation, resulting in privilege escalation and execution of unintended code. Successful exploitation requires the user to launch the affected external tool and to approve the elevation prompt without noticing that it refers to a different executable.