vendor:
GeekBuddy
by:
Jeremy Brown
7.2
CVSS
HIGH
Local Privilege Escalation
264
CWE
Product Name: GeekBuddy
Affected Version From: v4.18.121
Affected Version To: v4.18.121
Patch Exists: YES
Related CWE: CVE-2014-7872
CPE: a:comodo:geekbuddy
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows Server
2014
Comodo GeekBuddy Local Privilege Escalation (CVE-2014-7872)
Comodo GeekBuddy, which is bundled with Comodo Anti-Virus, Comodo Firewall and Comodo Internet Security, runs a passwordless, background VNC server and listens for incoming connections. This can allow for at least local privilege escalation on several platforms. It also may be remotely exploitable via CSRF-like attacks utilizing a modified web-based VNC client (eg. a Java VNC client).
Mitigation:
Comodo says they have fix this vulnerability with the v4.18.121 release in October 2014