Unquoted Service Path Vulnerability in Comodo Chromodo Browser
CVE-2016-20088

8.5HIGH

Key Information:

Vendor

Comodo

Vendor
CVE Published:
19 June 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2016-20088?

In Comodo's Chromodo Browser version 52.15.25.664, an unquoted service path vulnerability exists in the ChromodoUpdater service. This weakness allows local attackers to insert a malicious executable within the service path. As a result, when the service is restarted or the system is rebooted, the malicious code could be executed with elevated privileges. This makes the system susceptible to various security risks, as unauthorized code could potentially compromise the entire operating system.

Affected Version(s)

Chromodo Browser 0 <= 52.15.25.664

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yunus YILDIRIM (@Th3GundY)
.