CVE-2016-10717 – Malwarebytes Anti-Malware Bypass
SUMMARY:
A vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware allows an attacker to take control of the whitelisting feature (exclusions.dat under %SYSTEMDRIVE%\ProgramData) to permit execution of unauthorized applications including malware and malicious websites.
Files blacklisted by Malwarebytes Malware Protect can be executed, and domains blacklisted by Malwarebytes Web Protect can be reached through HTTP.
AFFECTED VERSIONS
- Malwarebytes Anti-Malware up to 2.2.1
PATCHED VERSIONS
- Malwarebytes Anti-Malware 3.0.4
MITIGATION ADVICE
We recommend upgrading the affected endpoints to the patched versions.
DETAILS
| CWE | CVS 3.x | CVS 2 | Impact |
| CWE CATEGORY: 7PK – Security Features | 7.8 High | 4.6 Medium | Local |
RECOGNITION
We thank Michael Spaling for bringing this issue to our attention.