Local Privilege Escalation Vulnerability in Comodo Internet Security Pro
CVE-2024-7251
What is CVE-2024-7251?
The cmdagent executable in Comodo Internet Security Pro has a vulnerability that enables local attackers to escalate their privileges. By leveraging the ability to execute low-privileged code on the system, an attacker can create a symbolic link that exploits this flaw. This enables the attacker to generate files using the agent and gain the capability to execute arbitrary code with elevated privileges in the context of the SYSTEM account. This security issue underscores the importance of securing access and monitoring executable permissions to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Internet Security Pro 12.2.4.8032
References
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
