PT-2021-11146 · Malwarebytes · Malwarebytes

Published

2021-01-15

·

Updated

2021-01-26

·

CVE-2020-25533

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Malwarebytes versions prior to 4.0
Description: An issue was discovered in Malwarebytes where a malicious application could perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct a situation where the same PID is used for running two different programs at different times, by leveraging a race condition during crafted use of posix spawn.
Recommendations: For versions prior to 4.0, update to version 4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Malwarebytes launch daemon to minimize the risk of exploitation.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25533

Affected Products

Malwarebytes