vendor:
Chromodo Browser
by:
Yunus YILDIRIM
7,2
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Chromodo Browser
Affected Version From: Software Version <= 52.15.25.664
Affected Version To: Software Version <= 52.15.25.664
Patch Exists: YES
Related CWE: N/A
CPE: a:comodo:chromodo_browser
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 x86/x64
2016
Comodo Chromodo Browser Unquoted Service Path Privilege Escalation
Comodo Chromodo Browser Update Service (ChromodoUpdater) installs as a service with an unquoted service path running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Mitigation:
Update to the latest version of Comodo Chromodo Browser (version 52.15.25.665)