CVE-2020-28641

HIGH

Malwarebytes Endpoint Protection < 1.2.0.849 - Arbitrary File Deletion via Symbolic Link

Title source: llm
STIX 2.1

Description

In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.

Scores

CVSS v3 7.1
EPSS 0.0076
EPSS Percentile 50.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-59
Status published
Products (2)
malwarebytes/endpoint_protection < 1.2.0.849
malwarebytes/malwarebytes 4.1.0.56
Published Dec 22, 2020
Tracked Since Feb 18, 2026