header-logo
Suggest Exploit
vendor:
Comodo Sandbox
by:
Joxean Koret
9,8
CVSS
CRITICAL
Comodo Sandbox Escape
287
CWE
Product Name: Comodo Sandbox
Affected Version From: Comodo Sandbox 5.0.0.0
Affected Version To: Comodo Sandbox 5.0.0.3
Patch Exists: YES
Related CWE: CVE-2018-15982
CPE: a:comodo:comodo_sandbox
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2018

Comodo Sandbox Escape

This exploit allows an attacker to escape from the Comodo Sandbox environment. The exploit is a proof-of-concept code that can be used to bypass the Comodo Sandbox security mechanism. The exploit works by creating a malicious executable file that is then executed in the sandbox environment. The malicious executable file contains code that will modify the system registry and allow the attacker to gain access to the system.

Mitigation:

Comodo has released a patch to address this vulnerability.
Source

Exploit-DB raw data:

Exploit: http://www.joxeankoret.com/download/comodo_sandbox_escape/sandbox_test1.tar.gz
Mirror: https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/34648.tar.gz (sandbox_test1.tar.gz)

Video: http://www.joxeankoret.com/download/comodo_sandbox_escape/video/sandbox_escape1.htm