First published: Thu Mar 23 2023(Updated: )
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Malwarebytes Anti-Malware | <4.5.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26088 has a medium severity rating due to its potential to allow arbitrary file deletion and privilege escalation.
To fix CVE-2023-26088, update Malwarebytes to version 4.5.23 or later.
Exploitation of CVE-2023-26088 can lead to unauthorized file deletions and may escalate user privileges on the affected system.
CVE-2023-26088 affects Malwarebytes versions prior to 4.5.23.
There are no known workarounds; the recommended action is to upgrade to the patched version of Malwarebytes.