QID 378632

Date Published: 2023-07-10

QID 378632: Telerik Fiddler Arbitrary Code Execution Vulnerability

Telerik Fiddler through 5.0.20202.18177 allows attackers to execute arbitrary programs via a hostname with a trailing space character, followed by --utility-and-browser --utility-cmd-prefix= and the pathname of a locally installed program.

Affected Version:

Telerik fiddler 5.0.20202.18177 and prior
QID Detection Logic(Authenticated):
Checks for the vulnerable version of fiddler.exe

Successful exploitation may lead to Arbitrary Code Execution

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to refer Fiddler v5.0.20204

    CVEs related to QID 378632

    Software Advisories
    Advisory ID Software Component Link
    Fiddler v5.0.20204 URL Logo www.telerik.com/support/whats-new/fiddler/release-history/fiddler-v5.0.20204