Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-3970

16
FAUCET Score

CVE-2019-3970 describes an Arbitrary File Write vulnerability in Comodo Antivirus versions up to 12.0.0.6810. A local, low-privileged attacker can modify the antivirus definition database by manipulating unsecured global section objects used by Cavwp.exe. This vulnerability has a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, allowing for high integrity impact (modification of virus signatures) without affecting confidentiality or availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in CISA's KEV catalog. Community discussion and media coverage are minimal, suggesting low public attention.

Impacted Technologies

VendorProductVersion(s)CPE
<= 12.0.0.6810CPE matchmatch criteria
cpe:2.3:a:comodo:antivirus:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

5.5MEDIUM

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.40%
Probability of exploitation in next 30 days
EPSS Percentile
32.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0040 is in the 88th percentile among its peer group of 15,932 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

aristavendor investigatingvia llm_extracted
naturalintelligencevendor investigatingvia llm_extracted
netgearvendor investigatingvia llm_extracted
opencartvendor investigatingvia llm_extracted
payloadcmsvendor investigatingvia llm_extracted
safarivendor investigatingvia llm_extracted

Vendor Advisories (6)

netgearllm-netgear-95d7021ab1ffcb5cMEDIUM

Comodo Antivirus Multiple Vulnerabilities

Jul 15, 2019
aristallm-arista-9e75c09d7b9af8a5MEDIUM

Comodo Antivirus Multiple Vulnerabilities

Jul 15, 2019
opencartllm-opencart-406df42f0dfa770dMEDIUM

Comodo Antivirus Multiple Vulnerabilities

Jul 15, 2019
safarillm-safari-a4007e278c031e50MEDIUM

Comodo Antivirus Multiple Vulnerabilities

Jul 15, 2019
naturalintelligencellm-naturalintelligence-166fddd2cba15703MEDIUM

Comodo Antivirus Multiple Vulnerabilities

Jul 15, 2019
payloadcmsllm-payloadcms-134da0e3747e02efMEDIUM

Comodo Antivirus Multiple Vulnerabilities

Jul 15, 2019

References

tenable.com / security/research/tra-2019-34
ExploitThird Party Advisory