Vulnerabilities > CVE-2023-36631 - Unspecified vulnerability in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
malwarebytes

Summary

Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password."

Vulnerable Configurations

Part Description Count
Application
Malwarebytes
1