Malwarebytes records
30 published records for vendor malwarebytes.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 3.3%
- Pre-auth RCE
- 3
- With a fix record
- 10%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation11
- CWE-59 Improper Link Resolution Before File Access ('Link Following')5
- CWE-426 Untrusted Search Path2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-190 Integer Overflow or Wraparound1
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
30 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2014-4936Weaponized | The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.101malwarebytes · malwarebytes anti-exploit · CWE-345 | Critical9.3 | — | 16.8% | Dec 16, 2014 |
40Plan | CVE-2024-25089No exploit | Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.malwarebytes · binisoft windows firewall control · CWE-94 | Critical9.8 | — | 1.8% | Feb 4, 2024 |
38Monitor | CVE-2019-6739No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711.malwarebytes · antimalware · CWE-78 | High8.8 | — | 9.9% | Jun 3, 2019 |
34Monitor | CVE-2022-50971No exploit | Malwarebytes 4.5 Unquoted Service Path Privilege Escalationmalwarebytes · malwarebytes · CWE-428 | High8.5 | — | 0.2% | Jun 19, 2026 |
31Monitor | CVE-2016-10717No exploit | A vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware consumer version 2.2.1 and prior (fixed in 3.0.malwarebytes · malwarebytes anti-malware · CWE-254 | High7.8 | — | 1.1% | Mar 21, 2018 |
31Monitor | CVE-2020-11507No exploit | An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a mmalwarebytes · adwcleaner · CWE-426 | High7.8 | — | 0.9% | Apr 6, 2020 |
31Monitor | CVE-2019-19929No exploit | An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges wmalwarebytes · adwcleaner · CWE-426 | High7.8 | — | 0.9% | Dec 22, 2019 |
31Monitor | CVE-2023-36631No exploit | Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windowmalwarebytes · binisoft windows firewall control | High7.8 | — | 0.7% | Jun 26, 2023 |
31Monitor | CVE-2018-5271No exploit | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unsmalwarebytes · malwarebytes · CWE-20 | High7.8 | — | 0.5% | Jan 8, 2018 |
31Monitor | CVE-2023-28892No exploit | Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.lomalwarebytes · adwcleaner · CWE-59 | High7.8 | — | 0.5% | Mar 29, 2023 |
31Monitor | CVE-2018-5279No exploit | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unsmalwarebytes · malwarebytes · CWE-20 | High7.8 | — | 0.5% | Jan 8, 2018 |
31Monitor | CVE-2023-26088No exploit | In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine systemmalwarebytes · malwarebytes · CWE-59 | High7.8 | — | 0.5% | Mar 22, 2023 |
31Monitor | CVE-2022-25150No exploit | In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.malwarebytes · binisoft windows firewall control · CWE-269 | High7.8 | — | 0.5% | Feb 14, 2022 |
31Monitor | CVE-2018-5276No exploit | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unsmalwarebytes · malwarebytes · CWE-20 | High7.8 | — | 0.4% | Jan 8, 2018 |
31Monitor | CVE-2018-5275No exploit | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unsmalwarebytes · malwarebytes · CWE-20 | High7.8 | — | 0.4% | Jan 8, 2018 |
31Monitor | CVE-2018-5274No exploit | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unsmalwarebytes · malwarebytes · CWE-20 | High7.8 | — | 0.4% | Jan 8, 2018 |
31Monitor | CVE-2018-5273No exploit | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unsmalwarebytes · malwarebytes · CWE-20 | High7.8 | — | 0.4% | Jan 8, 2018 |
31Monitor | CVE-2018-5277No exploit | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unsmalwarebytes · malwarebytes · CWE-20 | High7.8 | — | 0.4% | Jan 8, 2018 |
31Monitor | CVE-2018-5272No exploit | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unsmalwarebytes · malwarebytes · CWE-20 | High7.8 | — | 0.4% | Jan 8, 2018 |
31Monitor | CVE-2018-5270No exploit | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unsmalwarebytes · malwarebytes · CWE-20 | High7.8 | — | 0.4% | Jan 8, 2018 |
31Monitor | CVE-2023-29145No exploit | The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowimalwarebytes · endpoint detection and response · CWE-640 | High7.8 | — | 0.3% | Jun 30, 2023 |
31Monitor | CVE-2024-6260No exploit | Malwarebytes Antimalware Link Following Local Privilege Escalation Vulnerabilitymalwarebytes · antimalware · CWE-59 | High7.8 | — | 0.3% | Nov 22, 2024 |
28Monitor | CVE-2020-28641No exploit | In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.malwarebytes · endpoint protection · CWE-59 | High7.1 | — | 0.8% | Dec 22, 2020 |
28Monitor | CVE-2023-27469No exploit | Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileNamemalwarebytes · anti-exploit · CWE-59 | High7.1 | — | 0.4% | Jun 30, 2023 |
28Monitor | CVE-2020-25533No exploit | An issue was discovered in Malwarebytes before 4.0 on macOS.malwarebytes · malwarebytes · CWE-362 | High7.0 | — | 0.3% | Jan 15, 2021 |
- CVE-2014-493642Plan
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.101
CriticalCVSS 9.3WeaponizedEPSS 17%malwarebytes · malwarebytes anti-exploitDec 16, 2014
- CVE-2024-2508940Plan
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.
CriticalCVSS 9.8No exploitEPSS 2%malwarebytes · binisoft windows firewall controlFeb 4, 2024
- CVE-2019-673938Monitor
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711.
HighCVSS 8.8No exploitEPSS 10%malwarebytes · antimalwareJun 3, 2019
- CVE-2022-5097134Monitor
Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
HighCVSS 8.5No exploitEPSS 0%malwarebytes · malwarebytesJun 19, 2026
- CVE-2016-1071731Monitor
A vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware consumer version 2.2.1 and prior (fixed in 3.0.
HighCVSS 7.8No exploitEPSS 1%malwarebytes · malwarebytes anti-malwareMar 21, 2018
- CVE-2020-1150731Monitor
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner 8.0.3 could cause arbitrary code execution with SYSTEM privileges when a m
HighCVSS 7.8No exploitEPSS 1%malwarebytes · adwcleanerApr 6, 2020
- CVE-2019-1992931Monitor
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges w
HighCVSS 7.8No exploitEPSS 1%malwarebytes · adwcleanerDec 22, 2019
- CVE-2023-3663131Monitor
Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Window
HighCVSS 7.8No exploitEPSS 1%malwarebytes · binisoft windows firewall controlJun 26, 2023
- CVE-2018-527131Monitor
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have uns
HighCVSS 7.8No exploitEPSS 0%malwarebytes · malwarebytesJan 8, 2018
- CVE-2023-2889231Monitor
Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.lo
HighCVSS 7.8No exploitEPSS 0%malwarebytes · adwcleanerMar 29, 2023
- CVE-2018-527931Monitor
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have uns
HighCVSS 7.8No exploitEPSS 0%malwarebytes · malwarebytesJan 8, 2018
- CVE-2023-2608831Monitor
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system
HighCVSS 7.8No exploitEPSS 0%malwarebytes · malwarebytesMar 22, 2023
- CVE-2022-2515031Monitor
In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the Tools tab can be used to escalate privileges.
HighCVSS 7.8No exploitEPSS 0%malwarebytes · binisoft windows firewall controlFeb 14, 2022
- CVE-2018-527631Monitor
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have uns
HighCVSS 7.8No exploitEPSS 0%malwarebytes · malwarebytesJan 8, 2018
- CVE-2018-527531Monitor
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have uns
HighCVSS 7.8No exploitEPSS 0%malwarebytes · malwarebytesJan 8, 2018
- CVE-2018-527431Monitor
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have uns
HighCVSS 7.8No exploitEPSS 0%malwarebytes · malwarebytesJan 8, 2018
- CVE-2018-527331Monitor
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have uns
HighCVSS 7.8No exploitEPSS 0%malwarebytes · malwarebytesJan 8, 2018
- CVE-2018-527731Monitor
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have uns
HighCVSS 7.8No exploitEPSS 0%malwarebytes · malwarebytesJan 8, 2018
- CVE-2018-527231Monitor
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have uns
HighCVSS 7.8No exploitEPSS 0%malwarebytes · malwarebytesJan 8, 2018
- CVE-2018-527031Monitor
In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have uns
HighCVSS 7.8No exploitEPSS 0%malwarebytes · malwarebytesJan 8, 2018
- CVE-2023-2914531Monitor
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowi
HighCVSS 7.8No exploitEPSS 0%malwarebytes · endpoint detection and responseJun 30, 2023
- CVE-2024-626031Monitor
Malwarebytes Antimalware Link Following Local Privilege Escalation Vulnerability
HighCVSS 7.8No exploitEPSS 0%malwarebytes · antimalwareNov 22, 2024
- CVE-2020-2864128Monitor
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
HighCVSS 7.1No exploitEPSS 1%malwarebytes · endpoint protectionDec 22, 2020
- CVE-2023-2746928Monitor
Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileName
HighCVSS 7.1No exploitEPSS 0%malwarebytes · anti-exploitJun 30, 2023
- CVE-2020-2553328Monitor
An issue was discovered in Malwarebytes before 4.0 on macOS.
HighCVSS 7.0No exploitEPSS 0%malwarebytes · malwarebytesJan 15, 2021