Summary
This host is installed with Malwarebytes
Anti-Malware and is prone to man in the middle attack through it's upgrade functionality.
Impact
Successful exploitation will allow
remote attackers to execute arbitrary code by spoofing the update server and uploading an executable.
Impact Level: Application
Solution
Upgrade to version 2.0.3 or
later, For updates refer to https://www.malwarebytes.org
Insight
MBAM client does not verify the actual
installer it downloads. This is combined with the fact that MBAM starts the new client installer with full administrative privileges.
Affected
Malwarebytes Anti-Malware
(MBAM) Consumer versions before 2.0.3 on Windows
Detection
Get the installed version with the help
of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2014-4936 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities