First published: Mon Jun 26 2023(Updated: )
** DISPUTED ** Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Malwarebytes Binisoft Windows Firewall Control | =6.9.2.0 | |
=6.9.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-36631 is currently disputed as the vendor considers the behavior intended.
As per the vendor, CVE-2023-36631 is not considered a vulnerability that requires a fix.
CVE-2023-36631 affects Malwarebytes Binisoft Windows Firewall Control version 6.9.2.0.
Yes, local unprivileged users can bypass Windows Firewall restrictions via the user interface's rules tab due to CVE-2023-36631.
CVE-2023-36631 is not considered critical, but its impact can vary based on user access levels.