PT-2018-4886 · Malwarebytes · Malwarebytes Antimalware
Published
2018-03-21
·
Updated
2018-04-18
·
CVE-2016-10717
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Malwarebytes Anti-Malware versions prior to 3.0.4
Description
A vulnerability in the encryption and permission implementation allows an attacker to take control of the whitelisting feature, permitting execution of unauthorized applications, including malware and malicious websites. This enables files blacklisted by Malwarebytes Malware Protect to be executed, and domains blacklisted by Malwarebytes Web Protect to be reached through HTTP.
Recommendations
For Malwarebytes Anti-Malware versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Malwarebytes Antimalware