PT-2015-3647 · Malwarebytes · Malwarebytes Anti-Exploit
Published
2015-01-13
·
Updated
2015-01-14
·
CVE-2014-100039
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Malwarebytes Anti-Exploit versions prior to 1.05.1.2014
Description
The issue allows local users to cause a denial of service, resulting in a crash, by utilizing a crafted size in an unspecified IOCTL call. This triggers an out-of-bounds read.
Recommendations
For versions prior to 1.05.1.2014, update to version 1.05.1.2014 or later to resolve the issue. As a temporary workaround, consider restricting access to the mbae.sys module to minimize the risk of exploitation.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Malwarebytes Anti-Exploit