CVE-2014-7872

Comodo GeekBuddy < 4.18.120 - Unauthenticated Privilege Escalation via VNC Server

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-7872. PoCs published by Jeremy Brown.

AI-analyzed exploit summary This is a writeup describing a local privilege escalation vulnerability in Comodo GeekBuddy due to an unauthenticated VNC server. The exploit involves connecting to the VNC server on localhost to hijack an administrative session.

Description

Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges by connecting to the server.

Exploits (1)

exploitdb WRITEUP
by Jeremy Brown · textlocalwindows
https://www.exploit-db.com/exploits/37065

This is a writeup describing a local privilege escalation vulnerability in Comodo GeekBuddy due to an unauthenticated VNC server. The exploit involves connecting to the VNC server on localhost to hijack an administrative session.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Comodo GeekBuddy (versions before 4.18.121)
No auth needed
Prerequisites: Comodo GeekBuddy installed · Administrator or another user logged in to start the VNC server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/37065/
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/122355

Scores

EPSS 0.0104
EPSS Percentile 59.4%

Details

CWE
CWE-264
Status published
Products (1)
comodo/geekbuddy < 4.18.120
Published Jun 09, 2015
Tracked Since Feb 18, 2026