PT-2023-22169 · Malwarebytes · Malwarebytes Edr
Published
2023-06-30
·
Updated
2024-11-26
·
CVE-2023-29145
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Malwarebytes EDR version 1.0.11 for Linux
Description
The Malwarebytes EDR for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. An attacker can exploit this by setting
LD LIBRARY PATH, setting LD PRELOAD, or running an executable file in a debugger.Recommendations
For Malwarebytes EDR version 1.0.11 for Linux, as a temporary workaround, consider restricting the use of the vulnerable driver until a patch is available. Avoid setting
LD LIBRARY PATH or LD PRELOAD to minimize the risk of exploitation. Restrict access to the debugger for executable files to prevent potential attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Malwarebytes Edr