Executive brief
Comodo Dragon is a web browser focused on security and privacy. A vulnerability in its update service allows a local user with low privileges to gain full administrative control (SYSTEM) over the computer. This could allow an attacker to install persistent malware, access sensitive data, or disable security software by placing a malicious file in a specific location on the hard drive.
Technical details
The DragonUpdater service in Comodo Dragon Browser (versions <= 52.15.25.663) suffers from an unquoted service path vulnerability (CWE-428). The service binary path contains spaces and is not enclosed in quotation marks, and the service executes with SYSTEM privileges. A local attacker with permission to write to the parent directories (e.g., C:\) can place a malicious executable named 'program.exe' or similar to intercept the service execution. Upon a system reboot or service restart, the malicious code is executed with SYSTEM-level authority. This issue was addressed in version 52.15.25.664.
Affected products
- Comodo Dragon Browser up to 52.15.25.663
Timeline
- 2016-09-24: disclosed: Initial contact with vendor
- 2016-10-03: patched: Fixed version 52.15.25.664 released
- 2016-10-06: other: Exploit-DB entry published
- 2026-06-19: advisory: NVD/VulnCheck advisory published