Directory Traversal Vulnerability in Comodo Internet Security Pro
CVE-2024-7248

7.8HIGH

Key Information:

Vendor

Comodo

Vendor
CVE Published:
29 July 2024

What is CVE-2024-7248?

The directory traversal vulnerability in Comodo Internet Security Pro facilitates local privilege escalation for attackers. By exploiting improper validation in the update mechanism, an attacker who has access to low-privileged code execution can manipulate user-supplied paths during file operations. This potential exploitation enables them to escalate privileges and run arbitrary code under the SYSTEM context, which can lead to severe security implications for affected systems.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.