CVE-2023-27469 – Anti-Exploit DoS
and arbitrary file deletion
SUMMARY:
Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileNamePath lacks a ‘\0’ character.
AFFECTED VERSIONS
- Malwarebytes Anti-Exploit <= v4.4.0.220
PATCHED VERSIONS
- Malwarebytes Anti-Exploit > v4.4.0.220
MITIGATION ADVICE
We recommend upgrading the affected endpoints to the patched versions.
DETAILS
| CWE | CVS 3.x | Vector |
| CWE-166: Improper Handling of Missing Special Element | 6.8 Medium | Local |
RECOGNITION
Airbus Security