Command Execution Vulnerability in Comodo AntiVirus Software
CVE-2008-0470

Currently unrated

Key Information:

Vendor

Comodo

Vendor
CVE Published:
29 January 2008

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC๐ŸŸฃ EPSS 19%

What is CVE-2008-0470?

A vulnerability in an ActiveX control of Comodo AntiVirus 2.0 enables remote attackers to execute arbitrary commands on the affected systems via the ExecuteStr method. This flaw can be exploited without user interaction, allowing for a potential security breach that could lead to unauthorized access and control over the compromised systems.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

EPSS Score

19% chance of being exploited in the next 30 days.

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.