vendor:
Comodo Dragon Browser
by:
Yunus YILDIRIM
7,2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Comodo Dragon Browser
Affected Version From: Software Version <= 52.15.25.663
Affected Version To: Software Version <= 52.15.25.663
Patch Exists: YES
Related CWE: N/A
CPE: a:comodo:dragon_browser
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x86/x64
2016
Comodo Dragon Browser Unquoted Service Path Privilege Escalation
Comodo Dragon Browser Update Service (DragonUpdater) installs as a service with an unquoted service path running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Mitigation:
Update to the latest version of Comodo Dragon Browser (version 52.15.25.664) to fix the vulnerability.