CVE-2023-43687: Race Condition
An issue was discovered in Malwarebytes before 4.6.14.326 and before 5.1.5.116 (and Nebula 2020-10-21 and later). There is a Race condition that leads to code execution because of a lack of locks between file verification and execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-43687?
CVE-2023-43687 has a high severity due to its potential to allow arbitrary code execution.
How do I fix CVE-2023-43687?
To fix CVE-2023-43687, update Malwarebytes to version 4.6.14.326 or later, or to version 5.1.5.116 or later.
Which versions of Malwarebytes are affected by CVE-2023-43687?
CVE-2023-43687 affects Malwarebytes versions before 4.6.14.326 and 5.1.5.116, as well as Nebula versions released after 2020-10-21.
What is the nature of the vulnerability in CVE-2023-43687?
The vulnerability in CVE-2023-43687 is a race condition that occurs due to the lack of locks between file verification and execution.
Can CVE-2023-43687 be exploited remotely?
Yes, CVE-2023-43687 can potentially be exploited remotely, allowing an attacker to execute arbitrary code.