CVE-2020-25533 – Privilege Escalation in Malwarebytes for Mac

SUMMARY:

An issue was discovered in Malwarebytes for Mac before 4.0. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon.
The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct a situation where the same PID is used for running two different programs at different times, by leveraging a race condition during crafted use of posix_spawn.

AFFECTED VERSIONS

  • Malwarebytes for Mac < 4.0

PATCHED VERSIONS

  • Malwarebytes for Mac 4.0

MITIGATION ADVICE

We recommend upgrading the affected endpoints to the patched versions.

DETAILS

RECOGNITION

We would like to thank Wojciech Reguła for discovering this vulnerability.