CVE-2023-26088: High severity malwarebytes anti-malware vulnerability
Published Mar 23, 2023
·Updated
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.
Affected Software
1 affected component
Malwarebytes Malwarebytes Windows<4.5.23
Event History
Mar 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-26088?
CVE-2023-26088 has a medium severity rating due to its potential to allow arbitrary file deletion and privilege escalation.
2
How do I fix CVE-2023-26088?
To fix CVE-2023-26088, update Malwarebytes to version 4.5.23 or later.
3
What are the implications of CVE-2023-26088 if exploited?
Exploitation of CVE-2023-26088 can lead to unauthorized file deletions and may escalate user privileges on the affected system.
4
Which versions of Malwarebytes are affected by CVE-2023-26088?
CVE-2023-26088 affects Malwarebytes versions prior to 4.5.23.
5
Is there a workaround for CVE-2023-26088?
There are no known workarounds; the recommended action is to upgrade to the patched version of Malwarebytes.