First published: Tue Dec 22 2020(Updated: )
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Malwarebytes Endpoint Protection | <1.2.0.849 | |
Malwarebytes Anti-Malware | =4.1.0.56 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28641 is classified as a high-severity vulnerability.
To mitigate CVE-2020-28641, users should update to the latest version of Malwarebytes, as patches have been released addressing this issue.
CVE-2020-28641 allows an attacker to delete arbitrary files from the system by exploiting the local quarantine system.
CVE-2020-28641 affects Malwarebytes Free version 4.1.0.56 and certain versions of Malwarebytes Endpoint Protection.
CVE-2020-28641 is a local vulnerability that requires access to the affected system to be exploited.