BlackTree Security · Infrastructure · Automation · AI

Fiddler Classic Could Elevate the Wrong Signed Helper

Progress’s advisory fixes CVE-2026-77805, a Windows privilege-escalation flaw in Fiddler Classic before 6.0.20262.10021. Fiddler accepted an allowed publisher signature without verifying the exact helper.

A low-privileged local attacker must replace a helper with another validly signed binary from an allowed publisher. The user must launch it and approve its UAC prompt without noticing the substitution. Elevation occurs only if the helper requests it. This is neither remote exploitation nor signature forgery.

Update and verify

Install 6.0.20262.10021, released 5 October 2026, or later. Until then, avoid external tools or confirm each UAC prompt names the expected file. Inventory Windows workstations and verify the build.

Leave a Reply

Your email address will not be published. Required fields are marked *