High severity7.1NVD Advisory· Published Dec 22, 2020· Updated Jun 17, 2026
CVE-2020-28641
CVE-2020-28641
Description
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:a:malwarebytes:endpoint_protection:*:*:*:*:*:*:*:*Range: <1.2.0.849
cpe:2.3:a:malwarebytes:malwarebytes:4.1.0.56:*:*:*:free:windows:*:*+ 1 more
- cpe:2.3:a:malwarebytes:malwarebytes:4.1.0.56:*:*:*:free:windows:*:*
- (no CPE)range: = 4.1.0.56
- Malwarebytes/Malwarebytes Freedescription
Patches
Vulnerability mechanics
References
3- support.malwarebytes.com/hc/en-us/articles/1500000403501-Arbitrary-file-deletion-vulnerability-fixed-in-Malwarebytes-Endpoint-ProtectionnvdVendor Advisory
- support.malwarebytes.com/hc/en-us/articles/360058885974-Arbitrary-file-deletion-vulnerability-fixed-in-Malwarebytes-for-WindowsnvdVendor Advisory
- www.malwarebytes.comnvdProduct
News mentions
0No linked articles in our index yet.