在 Progress® Telerik® Fiddler® Classic for Windows 的 v6.0.20262.10021 之前的版本中,在安装 HTTPS 拦截根证书到本地计算机证书存储时存在一个检查时-使用时(TOCTOU)竞态条件。Fiddler 将证书写入用户可写位置中的临时文件,然后启动外部 TrustCert 辅助应用程序,该程序以提升权限并从该文件中导入证书。本地低权限威胁参与者在临时文件写入后到提升权限的辅助程序读取该文件之前替换临时文件,可以导致攻击者提供的根证书被安装到本地计算机受
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Progress® Telerik® Fiddler® Classic | 1.0.0 ~ 6.0.20262.10021 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92931 | 8.8 HIGH | CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK |
| CVE-2026-77805 | 7.9 HIGH | Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fiddler® Classi |
| CVE-2026-77802 | 6.3 MEDIUM | HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic |
| CVE-2026-77803 | 3.6 LOW | Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic |
No comments yet