CVE-2023-28888 – Malwarebytes
Anti-Ransomware – Privilege
Escalation

SUMMARY:

Due to Insufficient Checks on Existing ACLs and Insecure File Copy operations, Malwarebytes Anti-Ransomware suffers from a local Privilege Escalation to SYSTEM and DoS by creating %ProgramData%\Malwarebytes\MB3Service\config\ArwControllerConfig.json before installation.

AFFECTED VERSIONS

  • Anti Ransomware Setup <= 4.5.1.63
  • MBAMService.exe <= 3.2.0.1052

PATCHED VERSIONS

  • Anti Ransomware Setup > 4.5.1.63
  • MBAMService.exe > 3.2.0.1052

MITIGATION ADVICE

We recommend upgrading the affected endpoints to the patched versions.

DETAILS

CWECVS 3.xVector
CWE-269: Improper Privilege Management8.6 HighLocal