VYPR
Vendor

Malwarebytes

Products
17
CVEs
40
Across products
61
Status
Private

Products

17

Recent CVEs

40
View all 40 CVEs →
  • CVE-2024-25089CriFeb 4, 2024
    risk 0.64cvss 9.8epss 0.02

    Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.

  • CVE-2019-6739HigJun 3, 2019
    risk 0.58cvss 8.8epss 0.10

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page. There is an issue with the way…

  • CVE-2025-67905HigFeb 17, 2026
    risk 0.57cvss 8.7epss 0.00

    Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892.…

  • CVE-2023-29146HigJun 9, 2026
    risk 0.53cvss 8.2epss 0.00

    The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data if it exceeds 4GB. This leads to an integer wrap-around if the data is larger than the maximum unsigned integer value (32-bit). Attackers…

  • CVE-2022-50971HigJun 19, 2026
    risk 0.51cvss 7.8epss 0.00

    Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute…

  • CVE-2024-6260HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Malwarebytes Antimalware Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Malwarebytes Antimalware. An attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2023-29145HigJun 30, 2023
    risk 0.51cvss 7.8epss 0.00

    The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger.

  • CVE-2023-36631HigJun 26, 2023
    risk 0.51cvss 7.8epss 0.01

    Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application…

  • CVE-2023-28892HigMar 29, 2023
    risk 0.51cvss 7.8epss 0.00

    Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.

  • CVE-2023-26088HigMar 23, 2023
    risk 0.51cvss 7.8epss 0.00

    In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.

  • CVE-2022-25150HigFeb 14, 2022
    risk 0.51cvss 7.8epss 0.00

    In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.

  • CVE-2020-11507HigApr 6, 2020
    risk 0.51cvss 7.8epss 0.01

    An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded.

  • CVE-2019-19929HigDec 23, 2019
    risk 0.51cvss 7.8epss 0.01

    An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.

  • CVE-2016-10717HigMar 21, 2018
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware consumer version 2.2.1 and prior (fixed in 3.0.4) allows an attacker to take control of the whitelisting feature (exclusions.dat under %SYSTEMDRIVE%\ProgramData) to permit execution of…

  • CVE-2018-5279HigJan 8, 2018
    risk 0.51cvss 7.8epss 0.00

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e02c. NOTE: the vendor reported that they "have not been able…

  • CVE-2018-5277HigJan 8, 2018
    risk 0.51cvss 7.8epss 0.00

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e000. NOTE: the vendor reported that they "have not been able…

  • CVE-2018-5276HigJan 8, 2018
    risk 0.51cvss 7.8epss 0.00

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e018. NOTE: the vendor reported that they "have not been able…

  • CVE-2018-5275HigJan 8, 2018
    risk 0.51cvss 7.8epss 0.00

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E020. NOTE: the vendor reported that they "have not been able…

  • CVE-2018-5274HigJan 8, 2018
    risk 0.51cvss 7.8epss 0.00

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E024. NOTE: the vendor reported that they "have not been able…

  • CVE-2018-5273HigJan 8, 2018
    risk 0.51cvss 7.8epss 0.00

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e014. NOTE: the vendor reported that they "have not been able…