Progress Telerik Fiddler Classic < 6.0.20262.10021 Multiple Vulnerabilities

high Nessus Plugin ID 364359

Synopsis

The remote host is missing a security update.

Description

The version of Progress Telerik Fiddler Classic installed on the remote Windows host is prior to 6.0.20262.10021. It is, therefore, affected by multiple vulnerabilities:

- An insufficient integrity check on external helper tools allows a local low-privileged attacker to replace a helper executable with any validly signed binary from an allowed publisher and have it executed by the application, including with administrator privileges, resulting in privilege escalation. (CVE-2026-77805)

- A time-of-check time-of-use (TOCTOU) race condition exists in the HTTPS interception root certificate installation process. A local attacker with low privileges can substitute the temporary certificate file between write and import, causing an attacker-controlled certificate to be installed in the Local Computer Trusted Root store, enabling TLS traffic interception. (CVE-2026-77804)

- An HTTP request smuggling vulnerability exists in the proxy request forwarding component due to inconsistent interpretation of conflicting Content-Length headers. A low-privileged local attacker sharing the same proxy instance may exploit connection reuse to poison responses delivered to other users. (CVE-2026-77802)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Progress Telerik Fiddler Classic version 6.0.20262.10021 or later.

See Also

http://www.nessus.org/u?31ba4a50

http://www.nessus.org/u?70587cd2

http://www.nessus.org/u?7b97fbb4

http://www.nessus.org/u?be4d5c72

Plugin Details

Severity: High

ID: 364359

File Name: progress_telerik_fiddler_classic_6_0_20262_10021.nasl

Version: 1.1

Type: Local

Agent: windows

Family: Windows

Published: 10/9/2026

Updated: 10/9/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.8

Percentile: 96.49

CVSS v3

Risk Factor: High

Base Score: 7.9

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Vulnerability Information

CPE: cpe:/a:progress:telerik_fiddler_classic

Required KB Items: SMB/Registry/Enumerated, installed_sw/Progress Telerik Fiddler Classic

Patch Publication Date: 10/5/2026

Vulnerability Publication Date: 10/5/2026

Reference Information

CVE: CVE-2026-77802, CVE-2026-77803, CVE-2026-77804, CVE-2026-77805