Security Advisory

CVE-2019-18215

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-11-18 20:00:48
Last updated 2024-08-05 01:47:14
Assigner mitre
State PUBLISHED

Description

An issue was discovered in signmgr.dll 6.5.0.819 in Comodo Internet Security through 12.0. A DLL Preloading vulnerability allows an attacker to implant an unsigned DLL named iLog.dll in a partially unprotected product directory. This DLL is then loaded into a high-privileged service before the binary signature validation logic is loaded, and might bypass some of the self-defense mechanisms.