CVE-2014-4936: Critical severity malwarebytes anti-exploit vulnerability
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earlier allow man-in-the-middle attackers to execute arbitrary code by spoofing the update server and uploading an executable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4936?
CVE-2014-4936 is considered a critical vulnerability due to its potential for remote code execution by man-in-the-middle attackers.
How do I fix CVE-2014-4936?
To fix CVE-2014-4936, users should upgrade to Malwarebytes Anti-Malware version 2.0.3 or later and Malwarebytes Anti-Exploit version 1.04.1.1013 or later.
Which versions of Malwarebytes are affected by CVE-2014-4936?
CVE-2014-4936 affects Malwarebytes Anti-Malware versions prior to 2.0.3 and Malwarebytes Anti-Exploit versions prior to 1.04.1.1012.
What type of attack does CVE-2014-4936 enable?
CVE-2014-4936 enables an attacker to perform a man-in-the-middle attack to execute arbitrary code.
Is user interaction required to exploit CVE-2014-4936?
No, CVE-2014-4936 can be exploited without any user interaction, making it particularly dangerous.