CVE-2019-6739 – Malwarebytes Antimalware URI Handler Remote Command Execution Vulnerability
SUMMARY:
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711.
User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.
AFFECTED VERSIONS
- Malwarebytes Antimalware up to 3.6.1.2711
PATCHED VERSIONS
- Malwarebytes Antimalware > 3.6.1.2711
MITIGATION ADVICE
We recommend upgrading the affected endpoints to the patched versions.
DETAILS
| CWE | CVS 3.x | CVS 2 | Impact |
| CWE-77: Improper Neutralization of Special Elements used in a Command | 8.8 High | 6.8 Medium | Remote with user interaction |
RECOGNITION
We would like to thank ZDI and rgod of 9sg Security Team for their responsible disclosure of this issue.