Vulnerabilities > Malwarebytes > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-02-04 CVE-2024-25089 Unspecified vulnerability in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.
network
low complexity
malwarebytes
critical
9.8
2014-12-16 CVE-2014-4936 Insufficient Verification of Data Authenticity vulnerability in Malwarebytes products
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earlier allow man-in-the-middle attackers to execute arbitrary code by spoofing the update server and uploading an executable.
network
malwarebytes CWE-345
critical
9.3