CVE-2016-20088
Received
Received - Intake
Unquoted Service Path in Comodo Chromodo Browser
Publication date: 2026-06-19
Last updated on: 2026-06-19
Assigner: VulnCheck
Description
Description
Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that runs with SYSTEM privileges. A local attacker can insert a malicious executable in the service path and execute arbitrary code with elevated privileges upon service restart or system reboot.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| comodo | chromodo_browser | 52.15.25.664 |
| comodo | chromodo_browser | to 52.15.25.664 (inc) |
| comodo | chromodo_browser | From 52.15.25.665 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-428 | The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path. |