CVE-2023-29144 – Malwarebytes Endpoint Agent – Detection bypass

SUMMARY:

Malwarebytes Endpoint Agent for Linux before 1.1.64 and Malwarebytes for Windows v5 with an update package version < 1.0.104841, doesn’t properly compute signatures in some scenarios. This allows a bypass of detection.

AFFECTED VERSIONS

  • Endpoint Agent for Linux < 1.1.64
  • Malwarebytes for Windows v5 having an update package version <1.0.104841

PATCHED VERSIONS

  • Endpoint Agent for Linux >= 1.1.64
  • Malwarebytes for Windows v5 >= 5.3.0.186 | Update package version >= 1.0.104841

MITIGATION ADVICE

We recommend upgrading the affected endpoints to the patched versions.

DETAILS

CWECVS 3.xVector
CWE-190: Integer Overflow7.5 HighLocal