CWE
668
Advisory Published
Updated

CVE-2019-3970

First published: Wed Jul 17 2019(Updated: )

Comodo Antivirus versions up to 12.0.0.6810 are vulnerable to Arbitrary File Write due to Cavwp.exe handling of Comodo's Antivirus database. Cavwp.exe loads Comodo antivirus definition database in unsecured global section objects, allowing a local low privileged process to modify this data directly and change virus signatures.

Credit: vulnreport@tenable.com

Affected SoftwareAffected VersionHow to fix
Comodo Antivirus<=12.0.0.6810

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2019-3970?

    CVE-2019-3970 has a moderate severity rating due to its potential for arbitrary file write vulnerabilities.

  • How do I fix CVE-2019-3970?

    To mitigate CVE-2019-3970, users should upgrade to Comodo Antivirus version 12.0.0.6811 or later.

  • What software is affected by CVE-2019-3970?

    CVE-2019-3970 affects Comodo Antivirus versions up to and including 12.0.0.6810.

  • What is the nature of the vulnerability in CVE-2019-3970?

    CVE-2019-3970 is an Arbitrary File Write vulnerability caused by insecure handling of the antivirus database by the Cavwp.exe process.

  • Can CVE-2019-3970 be exploited remotely?

    No, CVE-2019-3970 requires local access for exploitation, as it allows a low privileged process to modify antivirus data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203