CVE-2025-67905: High severity Malwarebytes AdwCleaner vulnerability
Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an attacker must create a file in a given folder path and intercept the application log file deletion flow.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67905?
CVE-2025-67905 has a high severity rating due to the potential for privilege escalation to SYSTEM.
How do I fix CVE-2025-67905?
To fix CVE-2025-67905, upgrade Malwarebytes AdwCleaner to version 8.7.0 or later.
Who is affected by CVE-2025-67905?
Users of Malwarebytes AdwCleaner versions prior to 8.7.0 are affected by CVE-2025-67905.
What type of vulnerability is CVE-2025-67905?
CVE-2025-67905 is a privilege escalation vulnerability resulting from an insecure log file deletion mechanism.
Can CVE-2025-67905 be exploited remotely?
CVE-2025-67905 requires local access to exploit, making it not a remote vulnerability.