CVE-2022-34008

Comodo Antivirus 12.2.2.8012 has a quarantine flaw that allows privilege escalation. To escalate privilege, a low-privileged attacker can use an NTFS directory junction to restore a malicious DLL from quarantine into the System32 folder.
Configurations

Configuration 1 (hide)

cpe:2.3:a:comodo:antivirus:12.2.2.8012:*:*:*:*:*:*:*

History

21 Nov 2024, 07:08

Type Values Removed Values Added
References () https://antivirus.comodo.com/ - Product, Vendor Advisory () https://antivirus.comodo.com/ - Product, Vendor Advisory
References () https://r0h1rr1m.medium.com/comodo-antivirus-local-privilege-escalation-through-insecure-file-move-476a4601d9b8 - Exploit, Third Party Advisory () https://r0h1rr1m.medium.com/comodo-antivirus-local-privilege-escalation-through-insecure-file-move-476a4601d9b8 - Exploit, Third Party Advisory

08 Aug 2023, 14:22

Type Values Removed Values Added
CWE CWE-269 CWE-59

Information

Published : 2022-06-21 15:15

Updated : 2024-11-21 07:08


NVD link : CVE-2022-34008

Mitre link : CVE-2022-34008

CVE.ORG link : CVE-2022-34008


JSON object : View

Products Affected

comodo

  • antivirus
CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')