CVE-2025-67905 – Malwarebytes
AdwCleaner – Privilege Escalation
SUMMARY:
Malwarebytes AdwCleaner before 8.7.0 runs as Administrator and performs an insecure file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.
AFFECTED VERSIONS
- Malwarebytes AdwCleaner < 8.7.0
PATCHED VERSIONS
- >=8.7.0
MITIGATION ADVICE
We recommend upgrading the affected endpoints to the patched version.
DETAILS
| CWE | CVS 3.x | Vector |
| CWE-269: Improper Privilege Management | 8.6 High | Local |
RECOGNITION
Bocheng Xiang(@Crispr) From FDU