CVE-2021-43768 – Malwarebytes for Teams Local Privilege Escalation

SUMMARY:

In Malwarebytes for Teams 4.1.2.73 with component package version 1.0.990 and before, a low privileged user can execute local privilege escalation via COM interface.

AFFECTED VERSIONS

  • Component package version <= 1.0.990 of Malwarebytes for Teams 4.1.2.73

PATCHED VERSIONS

  • Component package version >= 1.0.1003 of Malwarebytes for Teams 4.1.2.73

MITIGATION ADVICE

We recommend upgrading the affected endpoints to the latest version.

DETAILS

CWECVS 3.xVectorImpact
CWE-269: Improper Privilege Management8.4 HighLocalLocal Privilege Escalation