CVE-2020-28641: High severity malwarebytes endpoint protection vulnerability
Published Dec 22, 2020
·Updated
In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.
Affected Software
2 affected components
Malwarebytes Endpoint Protection<1.2.0.849
Malwarebytes Malwarebytes Windows=4.1.0.56
Event History
Dec 22, 2020
CVE Published
via MITRE·10:07 PM
Data Sourced
via MITRE·10:07 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-28641?
CVE-2020-28641 is classified as a high-severity vulnerability.
2
How do I fix CVE-2020-28641?
To mitigate CVE-2020-28641, users should update to the latest version of Malwarebytes, as patches have been released addressing this issue.
3
What impact does CVE-2020-28641 have on my system?
CVE-2020-28641 allows an attacker to delete arbitrary files from the system by exploiting the local quarantine system.
4
Which versions of Malwarebytes are affected by CVE-2020-28641?
CVE-2020-28641 affects Malwarebytes Free version 4.1.0.56 and certain versions of Malwarebytes Endpoint Protection.
5
Is CVE-2020-28641 a remote or local vulnerability?
CVE-2020-28641 is a local vulnerability that requires access to the affected system to be exploited.