PT-2024-31233 · Malwarebytes · Malwarebytes Premium Security

Published

2024-10-01

·

Updated

2024-10-04

·

CVE-2024-44744

CVSS v3.1

5.7

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Malwarebytes Premium Security version 5.0.0.883
Description An issue in Malwarebytes Premium Security allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. It is noted that this issue requires admin privileges and that the contents cannot be altered by non-admin users.
Recommendations For Malwarebytes Premium Security version 5.0.0.883, consider restricting access to the directories where crafted binaries can be placed, as a temporary workaround, until a patch is available. Additionally, ensure that only authorized admin users have access to these directories to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-44744

Affected Products

Malwarebytes Premium Security