Vulnerabilities > Malwarebytes > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-30 CVE-2023-27469 Unspecified vulnerability in Malwarebytes Anti-Exploit
Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileNamePath lacks a '\0' character.
local
low complexity
malwarebytes
7.1
2023-06-30 CVE-2023-29145 Unspecified vulnerability in Malwarebytes Endpoint Detection and Response and Malwarebytes
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution.
local
low complexity
malwarebytes
7.8
2023-06-26 CVE-2023-36631 Unspecified vulnerability in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0
Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab.
local
low complexity
malwarebytes
7.8
2023-03-29 CVE-2023-28892 Link Following vulnerability in Malwarebytes Adwcleaner
Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.
local
low complexity
malwarebytes CWE-59
7.8
2018-01-08 CVE-2018-5279 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e02c.
local
low complexity
malwarebytes CWE-20
7.8
2018-01-08 CVE-2018-5278 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e00c.
local
low complexity
malwarebytes CWE-20
7.8
2018-01-08 CVE-2018-5277 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e000.
local
low complexity
malwarebytes CWE-20
7.8
2018-01-08 CVE-2018-5276 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e018.
local
low complexity
malwarebytes CWE-20
7.8
2018-01-08 CVE-2018-5275 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E020.
local
low complexity
malwarebytes CWE-20
7.8
2018-01-08 CVE-2018-5274 Improper Input Validation vulnerability in Malwarebytes 3.3.1.2183
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E024.
local
low complexity
malwarebytes CWE-20
7.8