Local Privilege Escalation Vulnerability in Comodo Internet Security Pro
CVE-2024-7251

7.8HIGH

Key Information:

Vendor

Comodo

Vendor
CVE Published:
29 July 2024

What is CVE-2024-7251?

The cmdagent executable in Comodo Internet Security Pro has a vulnerability that enables local attackers to escalate their privileges. By leveraging the ability to execute low-privileged code on the system, an attacker can create a symbolic link that exploits this flaw. This enables the attacker to generate files using the agent and gain the capability to execute arbitrary code with elevated privileges in the context of the SYSTEM account. This security issue underscores the importance of securing access and monitoring executable permissions to prevent exploitation.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.