CVE-2022-25150 – Windows Firewall Control Privilege Escalation

SUMMARY:

In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the
Tools tab can be used to escalate privileges.

AFFECTED VERSIONS

  • Malwarebytes Binisoft Windows Firewall Control < 6.8.1

PATCHED VERSIONS

  • Malwarebytes Binisoft Windows Firewall Control 6.8.1

MITIGATION ADVICE

We recommend upgrading the affected endpoints to the patched versions.

DETAILS

CWECVS 3.xCVS  2Impact
CWE-269: Improper Privilege Management7.8 High4.6 MediumLocal Privilege Escalation

RECOGNITION

We would like to thank Daniel “Living Computer” A. from Sweden for their H1 report, and the following of responsible vulnerability disclosure principles.