QID 378632
Date Published: 2023-07-10
QID 378632: Telerik Fiddler Arbitrary Code Execution Vulnerability
Telerik Fiddler through 5.0.20202.18177 allows attackers to execute arbitrary programs via a hostname with a trailing space character, followed by --utility-and-browser --utility-cmd-prefix= and the pathname of a locally installed program.
Affected Version:
Telerik fiddler 5.0.20202.18177 and prior
QID Detection Logic(Authenticated):
Checks for the vulnerable version of fiddler.exe
Successful exploitation may lead to Arbitrary Code Execution
Solution
Customers are advised to refer Fiddler v5.0.20204
Vendor References
CVEs related to QID 378632
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Fiddler v5.0.20204 |
|