CVE-2020-25533 – Privilege Escalation in Malwarebytes for Mac
SUMMARY:
An issue was discovered in Malwarebytes for Mac before 4.0. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon.
The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct a situation where the same PID is used for running two different programs at different times, by leveraging a race condition during crafted use of posix_spawn.
AFFECTED VERSIONS
- Malwarebytes for Mac < 4.0
PATCHED VERSIONS
- Malwarebytes for Mac 4.0
MITIGATION ADVICE
We recommend upgrading the affected endpoints to the patched versions.
DETAILS
| CWE | CVS 3.x | CVS 2 | Impact |
| CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization | 7.0 High | 6.9 Medium | Local |
RECOGNITION
We would like to thank Wojciech Reguła for discovering this vulnerability.