Back

HIGH

Comodo Dragon Browser 52.15.25.663 Privilege Escalation via Unquoted Service Path

Published Jun 19, 2026

Description

Comodo Dragon Browser versions up to 52.15.25.663 contain a privilege escalation vulnerability in the DragonUpdater service due to an unquoted service path running with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon service restart or system reboot.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jun 19, 2026
Updated Jun 22, 2026
Reserved Jun 19, 2026
CISA Vulnrichment
Updated Jun 22, 2026
NVD
Status Deferred
Modified Jun 22, 2026
Red Hat
Severity n/a
Public date n/a