CVE-2023-29145 – Malwarebytes
EDR for Linux – Arbitrary code
execution

SUMMARY:

The Malwarebytes EDR 1.0.11 for Linux driver doesn’t properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger.

AFFECTED VERSIONS

  • EDR for Linux <= 1.0.11
  • Malwarebytes for Linux <= 1.0.14

PATCHED VERSIONS

  • EDR for Linux: 1.0.56

MITIGATION ADVICE

We recommend upgrading the affected endpoints to the patched versions.

DETAILS

CWECVS 3.xVector
CWE-114: Process Control8.2 HighLocal