Unquoted Service Path Vulnerability in Comodo Chromodo Browser
CVE-2016-20088
Key Information:
- Vendor
Comodo
- Status
- Vendor
- CVE Published:
- 19 June 2026
Badges
What is CVE-2016-20088?
In Comodo's Chromodo Browser version 52.15.25.664, an unquoted service path vulnerability exists in the ChromodoUpdater service. This weakness allows local attackers to insert a malicious executable within the service path. As a result, when the service is restarted or the system is rebooted, the malicious code could be executed with elevated privileges. This makes the system susceptible to various security risks, as unauthorized code could potentially compromise the entire operating system.
Affected Version(s)
Chromodo Browser 0 <= 52.15.25.664
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
