Critical Comodo Internet Security 2025 Flaws Allow Remote Code Execution as SYSTEM
ID: 360aa936-43b5-51a6-9cbe-c8677ba466a2
STIX ID: report--360aa936-43b5-51a6-9cbe-c8677ba466a2
Feed Name: Cyber Press
Threat Score
**Executive summary:** Security researchers disclosed critical vulnerabilities in Comodo Internet Security 2025 that allow attackers on the same network to bypass SSL validation for updates, perform DNS/ARP spoofing to redirect update traffic, deliver malicious update packages that execute as SYSTEM, and leverage path traversal in manifests to drop persistent payloads; the report includes PoC commands and mitigation advice while patches are pending.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
