CVE-2019-6739 – Malwarebytes Antimalware URI Handler Remote Command Execution Vulnerability

SUMMARY:

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Malwarebytes Antimalware 3.6.1.2711.
User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.

AFFECTED VERSIONS

  • Malwarebytes Antimalware up to 3.6.1.2711

PATCHED VERSIONS

  • Malwarebytes Antimalware > 3.6.1.2711

MITIGATION ADVICE

We recommend upgrading the affected endpoints to the patched versions.

DETAILS

CWECVS 3.xCVS  2Impact
CWE-77: Improper Neutralization of Special Elements used in a Command8.8 High6.8 MediumRemote with user interaction

RECOGNITION

We would like to thank ZDI and rgod of 9sg Security Team for their responsible disclosure of this issue.