CVE-2025-7096
Last modified
CVE-2025-7096 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability affects unknown code of the file cis_update_x64.xml of the component Manifest File Handler. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability affects unknown code of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation leads to improper validation of integrity check value. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Comodo | Internet Security | 12.3.4.8162 |
References
- https://drive.google.com/file/d/1qnWarYsTSc5_sV6o8ULv0LBvGfKKXPxn/view?usp=sharingExploit, Third Party Advisory
- https://vuldb.com/?ctiid.315010Permissions Required, VDB Entry
- https://vuldb.com/?id.315010Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.603713Third Party Advisory, VDB Entry
- https://drive.google.com/file/d/1qnWarYsTSc5_sV6o8ULv0LBvGfKKXPxn/viewExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-7096?
How severe is CVE-2025-7096?
How do I fix CVE-2025-7096?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-70954A Null Pointer Dereference vulnerability exists in the TON V…7.5
- CVE-2025-70955A Stack Overflow vulnerability was discovered in the TON Vir…7.5
- CVE-2025-70956A State Pollution vulnerability was discovered in the TON Vi…7.5
- CVE-2025-70957A Denial of Service (DoS) vulnerability was discovered in th…7.5
- CVE-2025-70958Multiple reflected cross-site scripting (XSS) vulnerabilitie…6.1
- CVE-2025-70959A stored cross-site scripting (XSS) vulnerability in the Job…5.4
- CVE-2025-70960A stored cross-site scripting (XSS) vulnerability in the For…5.4
- CVE-2025-70962Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Acc…7.5
- CVE-2025-70963Gophish <=0.12.1 is vulnerable to Incorrect Access Control. …7.6
- CVE-2025-70968FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cp…9.8
- CVE-2025-7097A vulnerability, which was classified as critical, has been …8.8
- CVE-2025-70973ScadaBR 1.12.4 is vulnerable to Session Fixation. The applic…4.8
Are you affected by CVE-2025-7096?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
