7.2
CVSSv2

CVE-2014-7872

Published: 09/06/2015 Updated: 06/12/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Comodo GeekBuddy prior to 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges by connecting to the server.

Vulnerable Product Search on Vulmon Subscribe to Product

comodo geekbuddy

Exploits

Comodo GeekBuddy Local Privilege Escalation (CVE-2014-7872) Jeremy Brown [jbrown3264/gmail] -Synopsis- Comodo GeekBuddy, which is bundled with Comodo Anti-Virus, Comodo Firewall and Comodo Internet Security, runs a passwordless, background VNC server and listens for incoming connections This can allow for at least local privilege escalation on ...
Comodo GeekBuddy, which is bundled with Comodo Anti-Virus, Comodo Firewall, and Comodo Internet Security, runs a passwordless, background VNC server and listens for incoming connections This can allow for at least local privilege escalation on several platforms It also may be remotely exploitable via CSRF-like attacks utilizing a modified web-bas ...