CVE-2019-19929 – Untrusted Search Path vulnerability in AdwCleaner
SUMMARY:
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.
AFFECTED VERSIONS
- Malwarebytes AdwCleaner before 8.0.1
PATCHED VERSIONS
- Malwarebytes AdwCleaner 8.0.1
MITIGATION ADVICE
We recommend upgrading the affected endpoints to the patched versions.
DETAILS
| CWE | CVS 3.x | CVS 2 | Impact |
| CWE-426: Untrusted Search Path | 7.8 High | 6.9 Medium | Local |
RECOGNITION
We would like to thank Günter Born for bringing this issue to our attention.