PT-2025-28090 · Comodo · Comodo Internet Security Premium

Fpt Is Security

·

Published

2025-06-13

·

Updated

2025-07-11

·

CVE-2025-7096

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Comodo Internet Security Premium version 12.3.4.8162
Description: A critical vulnerability was found in the Manifest File Handler component of Comodo Internet Security Premium, affecting the file cis update x64.xml. This issue leads to improper validation of the integrity check value. The attack can be initiated remotely, with a rather high complexity, making exploitation difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted about this disclosure but did not respond.
Recommendations: For Comodo Internet Security Premium version 12.3.4.8162, as a temporary workaround, consider restricting access to the Manifest File Handler component until a patch is available. Avoid using the cis update x64.xml file in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

BDU:2025-13107
CVE-2025-7096

Affected Products

Comodo Internet Security Premium