PT-2021-11146 · Malwarebytes · Malwarebytes
Published
2021-01-15
·
Updated
2021-01-26
·
CVE-2020-25533
CVSS v3.1
7.0
High
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Malwarebytes versions prior to 4.0
Description:
An issue was discovered in Malwarebytes where a malicious application could perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct a situation where the same PID is used for running two different programs at different times, by leveraging a race condition during crafted use of
posix spawn.Recommendations:
For versions prior to 4.0, update to version 4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Malwarebytes launch daemon to minimize the risk of exploitation.
Exploit
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Malwarebytes