Impact
The vulnerability exposes privileged inter-process communication functionality in Progress Telerik Fiddler Everywhere (CWE‑749: Improper Restriction of Operations within a Component). A local attacker with low privileges who can modify the application’s launch arguments and persuade a user to start the program can replace the user interface or alter settings with content controlled by the attacker. This exploitation can lead to disclosure of OAuth authentication tokens, execution of locally accessible programs, or unauthorized modification of configuration files generated by the application.
Affected Systems
All instances of Progress Telerik Fiddler Everywhere that are earlier than version 8.2.0 are affected. The flaw resides in the privileged IPC routines that are active until the 8.2.0 release, which is the first version that implements the recommended mitigation changes.
Risk and Exploitability
The CVSS score of 5.6 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is local and requires the attacker to influence the user to launch the application with altered command‑line parameters. Because the exploitation relies on user interaction, the risk is reduced compared to remote code execution but remains significant for environments where users frequently run the software with custom shortcuts or scripts.
OpenCVE Enrichment