CVE-2014-100039 – Local DoS on
Malwarebytes Anti-Exploit
SUMMARY:
mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read. NOTE: some of these details are obtained from third party information.
AFFECTED VERSIONS
- Malwarebytes Anti-Exploit before 1.05.1.2014
PATCHED VERSIONS
- Malwarebytes Anti-Exploit 1.05.1.2014
MITIGATION ADVICE
We recommend upgrading the affected endpoints to the patched versions.
DETAILS
| CWE | CVS 3.x | CVS 2 | Impact |
| CWE-20: Improper Input Validation | N/A | 2.1 Low | Local |