CVE-2026-49494: Xcitium Client Security / Comodo Internet Security Remote Denial of Service
Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (CIS) through 12.3.4.8162 (fix expected by 2026 Q3) contain an integer underflow vulnerability in the firewall driver Inspect.sys that allows remote unauthenticated attackers to crash the system by sending a crafted IPv6 packet with a declared payload length smaller than the sum of its extension-header lengths. The unsigned 64-bit payload-length value underflows to a near-maximal integer, triggering an out-of-bounds read and oversized memcpy in the Windows kernel at DISPATCHLEVEL, resulting in a blue screen of death even on hosts with all ports blocked.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Xcitium Client Security (XCS)to a version that resolves this vulnerability.Fixed in 13.8.2.10019 - Configuration
Disable IPv6 on affected Windows hosts to prevent processing of crafted IPv6 packets that exploit the Inspect.sys integer underflow vulnerability.
Windows (IPv6 network stack) IPv6 = disabled - Compensating control
Block or filter IPv6 traffic at the network perimeter (firewalls/edge routers) to prevent delivery of crafted IPv6 packets with malicious extension headers that can trigger the Inspect.sys vulnerability.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-49494?
The severity of CVE-2026-49494 is rated high with a score of 7.5.
What type of vulnerability is associated with CVE-2026-49494?
CVE-2026-49494 is identified as an integer underflow vulnerability in the Comodo Internet Security's firewall driver.
How does CVE-2026-49494 affect Comodo Internet Security?
CVE-2026-49494 allows an attacker to exploit the integer underflow in Inspect.sys to perform a remote denial of service.
Is there a known fix for CVE-2026-49494?
Currently, the recommended action is to update to the latest version of Comodo Internet Security where the integer underflow vulnerability has been addressed.
Could CVE-2026-49494 lead to data loss?
While CVE-2026-49494 primarily results in a denial of service, it does not directly lead to data loss as it impacts availability.