CVE-2020-28641 – Arbitrary File Deletion
SUMMARY:
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
AFFECTED VERSIONS
- Endpoint Protection < 1.2.0.849
PATCHED VERSIONS
- Endpoint Protection: 1.2.0.849
MITIGATION ADVICE
We recommend upgrading the affected endpoints to the patched versions.
DETAILS
| CWE | CVS 3.x | CVS 2 | Impact |
| CWE-59: Improper Link Resolution Before File Access | 7.1 High | 6.6 Medium | Local |
RECOGNITION
Fortinet’s FortiGuard Labs