ZDI-CAN-22829: (0Day) Comodo Internet Security Pro cmdagent Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Comodo Internet Security Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-7250.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22829?
The severity of ZDI-CAN-22829 is critical as it allows for privilege escalation on affected systems.
How do I fix ZDI-CAN-22829?
To fix ZDI-CAN-22829, ensure that you are running the latest version of Comodo Internet Security Pro with all available patches applied.
Who is affected by ZDI-CAN-22829?
ZDI-CAN-22829 affects users of Comodo Internet Security Pro who have not updated to the patch addressing this vulnerability.
What type of attack does ZDI-CAN-22829 involve?
ZDI-CAN-22829 involves a local privilege escalation attack, requiring an attacker to execute low-privileged code on the system.
When was ZDI-CAN-22829 discovered?
ZDI-CAN-22829 was discovered and disclosed through the Zero Day Initiative vulnerability program.