CVE-2023-36631: High severity Malwarebytes Binisoft Windows Firewall Control vulnerability
DISPUTED Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36631?
The severity of CVE-2023-36631 is currently disputed as the vendor considers the behavior intended.
How do I fix CVE-2023-36631?
As per the vendor, CVE-2023-36631 is not considered a vulnerability that requires a fix.
What does CVE-2023-36631 affect?
CVE-2023-36631 affects Malwarebytes Binisoft Windows Firewall Control version 6.9.2.0.
Can users bypass Windows Firewall restrictions due to CVE-2023-36631?
Yes, local unprivileged users can bypass Windows Firewall restrictions via the user interface's rules tab due to CVE-2023-36631.
Is CVE-2023-36631 a critical vulnerability?
CVE-2023-36631 is not considered critical, but its impact can vary based on user access levels.