PT-2026-50908 · Comodo · Comodo Dragon Browser
CVE-2016-20090
·
Published
2026-06-19
·
Updated
2026-06-22
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Comodo Dragon Browser versions prior to 52.15.25.664
Description
The DragonUpdater service contains a privilege escalation flaw caused by an unquoted service path that runs with SYSTEM privileges. A local attacker can exploit this by placing a malicious executable within the service path, allowing for the execution of arbitrary code with elevated privileges when the service restarts or the system reboots.
Recommendations
Update Comodo Dragon Browser to version 52.15.25.664 or later.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Comodo Dragon Browser