CVE-2016-10717 – Malwarebytes Anti-Malware Bypass

SUMMARY:

A vulnerability in the encryption and permission implementation of Malwarebytes Anti-Malware allows an attacker to take control of the whitelisting feature (exclusions.dat under %SYSTEMDRIVE%\ProgramData) to permit execution of unauthorized applications including malware and malicious websites.
Files blacklisted by Malwarebytes Malware Protect can be executed, and domains blacklisted by Malwarebytes Web Protect can be reached through HTTP.

AFFECTED VERSIONS

  • Malwarebytes Anti-Malware up to 2.2.1

PATCHED VERSIONS

  • Malwarebytes Anti-Malware 3.0.4

MITIGATION ADVICE

We recommend upgrading the affected endpoints to the patched versions.

DETAILS

CWECVS 3.xCVS  2Impact
CWE CATEGORY: 7PK – Security Features7.8 High4.6 MediumLocal

RECOGNITION

We thank Michael Spaling for bringing this issue to our attention.