Comodo Internet Security Premium
cpe:2.3:a:comodo:comodo_internet_security:*:*:*:*:*:*:*, +1 more
- 12.3.4.8162
A critical path traversal vulnerability has been identified in Comodo Internet Security Premium version 12.3.4.8162. The issue arises in the File Name Handler component, where the application improperly validates the 'name' or 'folder' argument. This flaw allows for arbitrary file writes, as the application uses the unvalidated input to determine download file names, potentially leading to the execution of malicious files with SYSTEM privileges.
Exploitation of this vulnerability allows for arbitrary file writes, which can be used to deliver persistent malware. After a system reboot, the malware can execute, providing remote control over the affected machine. Although the malicious file runs under Comodo's isolation, it can use post-exploitation techniques to bypass User Account Control and gain SYSTEM privileges, allowing access to sensitive system credentials.
The vulnerability can be reproduced by crafting a path traversal payload that exploits the improper validation of the 'name' or 'folder' argument in the File Name Handler component. This payload can be included in a manifest file, which, when processed by Comodo Internet Security, will write a malicious file into the startup folder. Once the victim reboots their machine, the malware will execute, establishing a remote connection back to the attacker.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.