CVE-2025-7096 Details
Description
A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability affects unknown code of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation leads to improper validation of integrity check value. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A critical vulnerability exists in Comodo Internet Security Premium version 12.3.4.8162, specifically within the Manifest File Handler component. The issue arises from the application's failure to properly validate the integrity of the 'cis_update_x64.xml' file, which is used to manage update metadata. This flaw allows remote attackers to manipulate the update process, potentially leading to the execution of malicious scripts with SYSTEM privileges. The vulnerability is exacerbated by a path traversal issue, enabling arbitrary file writes that could be exploited to deliver persistent malware.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 7, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://drive.google.com/file/d/1qnWarYsTSc5_sV6o8ULv0LBvGfKKXPxn/view | CISA-ADP | ExploitThird Party Advisory |
| https://drive.google.com/file/d/1qnWarYsTSc5_sV6o8ULv0LBvGfKKXPxn/view?usp=sharing | [email protected] | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.315010 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.315010 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.603713 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-354 | Improper Validation of Integrity Check Value | [email protected] |
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
| CWE-354 | Improper Validation of Integrity Check Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| comodo internet security | 12.3.4.8162 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 18, 2025 | Initial Analysis | [email protected] |
| Jul 7, 2025 | CVE Modified | CISA-ADP |
| Jul 6, 2025 | New CVE Received | [email protected] |