CVE-2019-19929 – Untrusted Search Path vulnerability in AdwCleaner

SUMMARY:

An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.

AFFECTED VERSIONS

  • Malwarebytes AdwCleaner before 8.0.1

PATCHED VERSIONS

  • Malwarebytes AdwCleaner 8.0.1

MITIGATION ADVICE

We recommend upgrading the affected endpoints to the patched versions.

DETAILS

CWECVS 3.xCVS  2Impact
CWE-426: Untrusted Search Path7.8 High6.9 MediumLocal

RECOGNITION

We would like to thank Günter Born for bringing this issue to our attention.