CVE-2022-25150 – Windows Firewall Control Privilege Escalation
SUMMARY:
In Malwarebytes Binisoft Windows Firewall Control before 6.8.1.0, programs executed from the
Tools tab can be used to escalate privileges.
AFFECTED VERSIONS
- Malwarebytes Binisoft Windows Firewall Control < 6.8.1
PATCHED VERSIONS
- Malwarebytes Binisoft Windows Firewall Control 6.8.1
MITIGATION ADVICE
We recommend upgrading the affected endpoints to the patched versions.
DETAILS
| CWE | CVS 3.x | CVS 2 | Impact |
| CWE-269: Improper Privilege Management | 7.8 High | 4.6 Medium | Local Privilege Escalation |
RECOGNITION
We would like to thank Daniel “Living Computer” A. from Sweden for their H1 report, and the following of responsible vulnerability disclosure principles.