logo

Critical Comodo Internet Security 2025 Flaws Allow Remote Code Execution as SYSTEM

ID: 360aa936-43b5-51a6-9cbe-c8677ba466a2

STIX ID: report--360aa936-43b5-51a6-9cbe-c8677ba466a2

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2025-07-07

Date Updated: 2026-04-19

Author: AnuPriya

...
...

**Executive summary:** Security researchers disclosed critical vulnerabilities in Comodo Internet Security 2025 that allow attackers on the same network to bypass SSL validation for updates, perform DNS/ARP spoofing to redirect update traffic, deliver malicious update packages that execute as SYSTEM, and leverage path traversal in manifests to drop persistent payloads; the report includes PoC commands and mitigation advice while patches are pending.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.