PT-2023-25644 · Malwarebytes · Malwarebytes Binisoft Windows Firewall Control

CVE-2023-36631

·

Publicado

2023-06-26

·

Atualizado

2024-09-11

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Malwarebytes Binisoft Windows Firewall Control version 6.9.2.0
Description The issue concerns a lack of access control in the wfc.exe component of Malwarebytes Binisoft Windows Firewall Control, allowing local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. The vendor considers this behavior intended, as the application can be locked using a password.
Recommendations For Malwarebytes Binisoft Windows Firewall Control version 6.9.2.0, consider locking the application using a password to restrict unauthorized access, as suggested by the vendor's perspective on the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-36631

Produtos afetados

Malwarebytes Binisoft Windows Firewall Control