PT-2025-28090 · Comodo · Comodo Internet Security Premium
Fpt Is Security
·
Published
2025-06-13
·
Updated
2025-07-11
·
CVE-2025-7096
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Comodo Internet Security Premium version 12.3.4.8162
Description:
A critical vulnerability was found in the Manifest File Handler component of Comodo Internet Security Premium, affecting the file cis update x64.xml. This issue leads to improper validation of the integrity check value. The attack can be initiated remotely, with a rather high complexity, making exploitation difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted about this disclosure but did not respond.
Recommendations:
For Comodo Internet Security Premium version 12.3.4.8162, as a temporary workaround, consider restricting access to the Manifest File Handler component until a patch is available. Avoid using the
cis update x64.xml file in the affected component to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Comodo Internet Security Premium