CVE-2019-12097: High severity progress telerik fiddler classic vulnerability
Published Jun 3, 2019
·Updated
Telerik Fiddler v5.0.20182.28034 doesn't verify the hash of EnableLoopback.exe before running it, which could lead to code execution or local privilege escalation by replacing the original EnableLoopback.exe.
Affected Software
1 affected component
Progress Fiddler=5.0.20182.28034
Event History
Jun 3, 2019
CVE Published
via MITRE·08:26 PM
Data Sourced
via MITRE·08:26 PM
Description
Frequently Asked Questions
1
What is CVE-2019-12097?
CVE-2019-12097 is a vulnerability in Telerik Fiddler v5.0.20182.28034 that allows code execution or local privilege escalation by replacing the original EnableLoopback.exe.
2
How severe is CVE-2019-12097?
CVE-2019-12097 has a severity score of 7.8 out of 10, indicating a high level of severity.
3
Which software versions are affected by CVE-2019-12097?
Telerik Fiddler v5.0.20182.28034 is affected by CVE-2019-12097.
4
How can I fix CVE-2019-12097?
To fix CVE-2019-12097, update Telerik Fiddler to a version that verifies the hash of EnableLoopback.exe before running it.
5
What is the Common Weakness Enumeration (CWE) for CVE-2019-12097?
The Common Weakness Enumeration (CWE) for CVE-2019-12097 is CWE-354.