CVE-2022-50971: Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during service startup or system reboot.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Remediate the unquoted service path privilege escalation in Malwarebytes 4.5 (MBAMService) by ensuring the service executable path used at startup/reboot is properly quoted and does not allow execution from an untrusted directory.
Event History
Frequently Asked Questions
What is the severity of CVE-2022-50971?
The severity of CVE-2022-50971 is rated as high with a score of 8.5.
How do I fix CVE-2022-50971?
To fix CVE-2022-50971, update Malwarebytes to the latest version that addresses this unquoted service path vulnerability.
What does CVE-2022-50971 affect?
CVE-2022-50971 affects Malwarebytes 4.5 and allows local attackers to escalate privileges.
How is CVE-2022-50971 exploited?
CVE-2022-50971 can be exploited by placing malicious executable files in unquoted service path directories.
What are the potential impacts of CVE-2022-50971?
The potential impacts of CVE-2022-50971 include privilege escalation and the execution of malicious code with LocalSystem privileges.