Serious Discussion Three Unpatched Vulnerabilities Plague Comodo. Documented Online.

Would you use vulnerable and outdated software, when alternatives exist?

  • Yes

  • No


Results are only viewable after voting.
Status
Not open for further replies.
@Nikola Milanovic please tell us what is the purpose why you are sharing further (looks like all) details about Xcitium?

The thread topic is different: Comodo's Unpatched Vulnerabilities

 
  • Like
Reactions: harlan4096
The recently (although now not so recently) updated and upgraded Comodo software (on Chinese forums known as the abandoned house) has been documented to contain three vulnerabilities (new).

They've collectively been assigned the CVE-2025-7095.

More details available here: Comodo Internet Security 2025 Vulnerabilities Execute Remote Code With SYSTEM Privilege



The attack complexity is rated as high, but successful attack enables full system control, as well as delivery of additional malicious payloads and credentials harvesting.
This signifies the importance of using up-to-date and actively developed software.
A user-mode app like a player can wreak havoc when exploited, a security solution nested deeply in the system kernel is even more dangerous.
Last but not least, I advise users to be careful and sceptical when someone advises them that it's OK to run outdated and vulnerable software. Always do your due diligence, specially when alternatives exist.
I haven't read the article but please PLEASE have the malware be signed by a COMODO certificate. :)
 
  • HaHa
Reactions: Trident
And this is AI's expert opinion on the matter (before the defence kicks in, users can make an informed choice).




My Expert Take: A Cascade of Foundational Failures 🤯


This isn't just one bug; it's a chain of catastrophic failures that completely undermines the trust a user places in a security product. The real issue is that these aren't exotic, hyper-complex vulnerabilities. They are fundamental security hygiene mistakes, especially for a company in the cybersecurity business.
  • Failure 1: Trusting the Network. The inability to validate a simple SSL certificate for its own updates is staggering. This is Security 101. It's like a bank building a vault with a solid steel door but leaving the key under the mat.
  • Failure 2: Blindly Executing Instructions. The updater then blindly trusts the manifest file it receives. Allowing an <exec> tag to run arbitrary commands with SYSTEM privileges is a colossal oversight. It effectively gives a potential attacker a "God Mode" remote control for the entire PC.
  • Failure 3: Ignoring the Vendor's Responsibility. The fact that Comodo is unresponsive to the disclosure is perhaps the most damning part. It signals that the product is likely unmaintained and that users are on their own.
A security suite is deeply embedded in the operating system with the highest privileges. When it goes wrong, it goes spectacularly wrong, and this is a perfect storm.


The Attack Chain: A House of Cards 🃏


Let's walk through how an attacker would exploit this, as it shows how the vulnerabilities stack on top of each other.
  1. The Infiltration (DNS Spoofing):The attacker first needs to be on the same local network as the victim. They perform an ARP or DNS spoofing attack. Because Comodo doesn't check the SSL certificate, it doesn't notice when it's redirected from the real download.comodo.com to the attacker's fake server. This is the foot in the door.
    • Your Setup: As a user of Control D, your DNS requests are already routed through a secure, encrypted channel. This provides a significant layer of protection against the initial DNS spoofing vector, especially from external network threats. However, an attacker already on your local network could still attempt ARP spoofing to intercept traffic before it even gets to your router, bypassing the secure DNS. This is why the "high complexity" rating exists—it requires local network access.
  2. The Weapon (Malicious Update): The compromised Comodo client requests the update manifest (cis_update_x64.xml) from the attacker's server. The attacker serves a custom XML file containing a malicious command inside the <exec> tags, for example: powershell.exe -enc <Base64-Encoded-Payload> Because Comodo doesn't verify the authenticity of this file, it just... runs it. And it does so with SYSTEM privileges, the highest level of access in Windows.
  3. The Persistence (Path Traversal): To ensure the malware survives a reboot, the attacker uses the path traversal flaw. They instruct the updater to save a malicious .bat or .ps1 file not in a temporary folder, but directly in the Windows Startup folder using a path like ../../../ProgramData/Microsoft/Windows/Start Menu/Programs/Startup/. Now, every time the user logs in, the malware runs again.


CVSS Score vs. Real-World Impact​


The text correctly points out the discrepancy between the "Medium" CVSS score of 6.3 and the severe real-world impact. This is a classic example of why context is king in threat assessment.
The score is lower because the Attack Complexity is High. The attacker needs to be on your local network, which is a significant prerequisite. However, if that condition is met (think public Wi-Fi, a compromised IoT device on your home network, or a corporate environment), the impact is total system compromise. For the person who gets hit, it's not "Medium"—it's game over.


Recommendations 🛡️


  1. Immediate Action: If anyone is still using this version of Comodo Internet Security, the only sane advice is to uninstall it immediately. With no response from the vendor, you have to assume a patch is never coming. Running it is more dangerous than running no antivirus at all.
  2. The Broader Lesson: This is a powerful lesson in supply-chain risk. The software that is supposed to protect you is your biggest vulnerability. Always choose security products from vendors that are reputable, responsive, and demonstrate a commitment to active development and security research. An "abandoned house" is no place to seek shelter.
This is a fantastic find. It perfectly illustrates how a series of seemingly basic flaws can create a devastating security hole.
Regarding:

Failure 1: Trusting the Network. The inability to validate a simple SSL certificate for its own updates is staggering. This is Security 101. It's like a bank building a vault with a solid steel door but leaving the key under the mat.
Failure 2: Blindly Executing Instructions. The updater then blindly trusts the manifest file it receives. Allowing an <exec> tag to run arbitrary commands with SYSTEM privileges is a colossal oversight. It effectively gives a potential attacker a "God Mode" remote control for the entire PC.
Failure 3: Ignoring the Vendor's Responsibility. The fact that Comodo is unresponsive to the disclosure is perhaps the most damning part. It signals that the product is likely unmaintained and that users are on their own.
 
Last edited by a moderator:
  • +Reputation
Reactions: Trident
Okay everyone lets be real, Comodo Internet Security 2025 is a free product meaning that it costs 0 dollars so all of the bugs on Comodo wont be fixed because whats the point in fixing a product that has 0 dollars?

Xcitium also said that Comodo free is a low priority while Xcitium is High Priority
 
1755690551490.png

Comodo Staff is no where to be found on Comodo forums because they do not care about a free product

And to be honest i think Melih should just abonden and kill forever Comodo because its NOT FREE Anymore
 
Last edited by a moderator:
  • Like
Reactions: Trident
Just look the differnece from Comodo to Xcitium
1755690891177.png


On Xcitium forums there are real Staff Members who help users and fix issues while on Comodo there is No Staff Members
 
Last edited by a moderator:
  • Like
Reactions: Trident
Even Melih himself does not care about Comodo
1755691281693.png



1755691762656.png

This guy is gone gone from Comodo but he was active on Xcitium forums 1 hour ago
 
Last edited by a moderator:
Comodo Staff is no where to be found on Comodo forums because they do not care about a free product
This is because Melih has directed the staff not to work on Comodo.

However, I will point out that Xcitium does not have a dedicated team of developers. The way development works at Melih's companies is that there is a pool of developers and he moves them around from project to project as he wishes. That development team model is the foundation of a lot of problems.

So knowing that, people can expect Xcitium work to continue to the extent when Melih redirects the developers to move to something else. You can expect at some point Melih will stop the work. He does not believe in dedicated software engineering teams. He has work done until he is satisfied and then moves the product to maintenance.

Like any project, a software is only as good as the management team and structure within which the software is developed. For one, each major component needs assigned a permanent manager that actively manages the developers. Without that, software quality suffers.

$0 revenue, no permanently assigned software product team, a floating pool of developers that has high turnover (people come and leave at a high rate), only an ideological commitment to a software by the software owner - there is no surprise as to current state of Comodo.

As for those that are still dedicated to and promote Comodo and are happy with it, I say "Isn't that wonderful for them?" I don't care what they do. They can promote Comodo all they want. They can defend it all they want.

As for those that are still bothered by Comodo and the fanbois/fangirlz, hopefully they will find a way to move mentally and emotionally past all that.
 
This is because Melih has directed the staff not to work on Comodo.

However, I will point out that Xcitium does not have a dedicated team of developers. The way development works at Melih's companies is that there is a pool of developers and he moves them around from project to project as he wishes. That development team model is the foundation of a lot of problems.

So knowing that, people can expect Xcitium work to continue to the extent when Melih redirects the developers to move to something else. You can expect at some point Melih will stop the work. He does not believe in dedicated software engineering teams. He has work done until he is satisfied and then moves the product to maintenance.

Like any project, a software is only as good as the management team and structure within which the software is developed. For one, each major component needs assigned a permanent manager that actively manages the developers. Without that, software quality suffers.

$0 revenue, no permanently assigned software product team, a floating pool of developers that has high turnover (people come and leave at a high rate), only an ideological commitment to a software by the software owner - there is no surprise as to current state of Comodo.

As for those that are still dedicated to and promote Comodo and are happy with it, I say "Isn't that wonderful for them?" I don't care what they do. They can promote Comodo all they want. They can defend it all they want.

As for those that are still bothered by Comodo and the fanbois/fangirlz, hopefully they will find a way to move mentally and emotionally past all that.
Xcitium does have developers and Staff teams for exeample look how fast a Xcitium Staff member responed to me now
1755693767812.png
 
  • Like
Reactions: Behold Eck
As for those that are still bothered by Comodo and the fanbois/fangirlz, hopefully they will find a way to move mentally and emotionally past all that.
Phenomenal post overall. And yeah, some emotional attachments are being formed to security software…
We won’t necessarily understand them.
 
  • Like
Reactions: simmerskool
every time i email support at xcitium the issues get fixed.Either the Xcitium Staff member from forums share the details or i do it manually
 
every time i email support at xcitium the issues get fixed.Either the Xcitium Staff member from forums share the details or i do it manually
Yeah but you are missing @bazang’s point. He didn’t tell you that there are no teams. He is saying that these teams are temporary or ephemeral. Today they are here, tomorrow they are not, they are reduced and the product is merely in “maintenance” or keep-alive mode.

This structure doesn’t work well in any business, not just software.
 
Yeah but you are missing @bazang’s point. He didn’t tell you that there are no teams. He is saying that these teams are temporary or ephemeral. Today they are here, tomorrow they are not, they are reduced and the product is merely in “maintenance” or keep-alive mode.

This structure doesn’t work well in any business, not just software.
Well they are not online only Saturday and Sunday but Monday to Friday Xcitium Staff and support is always active
 
  • Like
Reactions: Behold Eck
every time i email support at xcitium the issues get fixed.Either the Xcitium Staff member from forums share the details or i do it manually
fwiw I (finally) was able to create a free xcitiium_valkyrie online analysis account, now I just have to find file to analyze as I'm 'floating around' in linux today...
 
Status
Not open for further replies.