CVE-2026-77804: Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Progress® Telerik® Fiddler® Classic
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the certificate to a temporary file in a user-writable location and then launches the external TrustCert helper application, which elevates and imports the certificate from that file. A local threat actor with low privileges who replaces the temporary file between the time it is written and the time the elevated helper reads it can cause an attacker-supplied root certificate to be installed in the Local Computer Trusted Root Certification Authorities store, enabling subsequent interception and modification of TLS-protected traffic on the machine. Successful exploitation requires the user to initiate the certificate trust operation and approve the elevation prompt.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Telerik Fiddler Classic for Windowsto a version that resolves this vulnerability.Fixed in 6.0.20262.10021
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Systems running Progress Telerik Fiddler Classic for Windows before v6.0.20262.10021 are exposed when a user initiates the HTTPS interception root certificate trust operation. The attacker must already have low-privileged local access to the machine.
Does exploitation require user interaction or elevation approval?
Yes. A user must start the certificate trust operation and approve the elevation prompt for the TrustCert helper application. The attacker must replace the temporary certificate file before the elevated helper reads it.
What is the impact if exploitation succeeds?
An attacker-supplied root certificate can be installed in the Local Computer Trusted Root Certification Authorities store. This can enable later interception and modification of TLS-protected traffic on that machine.
How can I determine whether a system is affected?
Check whether Progress Telerik Fiddler Classic for Windows is installed at a version earlier than v6.0.20262.10021. Also review the Local Computer Trusted Root Certification Authorities store for unexpected root certificates if the certificate trust operation may have been performed on a system accessible to low-privileged local users.