Local Privilege Escalation Vulnerability in Comodo Internet Security Pro
CVE-2024-7251
7.8HIGH
What is CVE-2024-7251?
The cmdagent executable in Comodo Internet Security Pro has a vulnerability that enables local attackers to escalate their privileges. By leveraging the ability to execute low-privileged code on the system, an attacker can create a symbolic link that exploits this flaw. This enables the attacker to generate files using the agent and gain the capability to execute arbitrary code with elevated privileges in the context of the SYSTEM account. This security issue underscores the importance of securing access and monitoring executable permissions to prevent exploitation.