CVE-2022-50971

HIGH

Malwarebytes 4.5 Unquoted Service Path Privilege Escalation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2022-50971. PoCs published by Hejap Zairy Al-Sharif.

AI-analyzed exploit summary The exploit describes an unquoted service path vulnerability in Malwarebytes 4.5, where the service path lacks quotes, potentially allowing local privilege escalation if an attacker can place a malicious executable in the system root path. The provided output from 'sc qc MBAMService' confirms the vulnerable path.

Description

Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during service startup or system reboot.

Exploits (1)

exploitdb WRITEUP
by Hejap Zairy Al-Sharif · textlocalwindows
https://www.exploit-db.com/exploits/50806

The exploit describes an unquoted service path vulnerability in Malwarebytes 4.5, where the service path lacks quotes, potentially allowing local privilege escalation if an attacker can place a malicious executable in the system root path. The provided output from 'sc qc MBAMService' confirms the vulnerable path.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: Malwarebytes 4.5.0
Auth required
Prerequisites: local user access · ability to write to system root path
devstral-2 · analyzed Jun 19, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-50806
https://www.exploit-db.com/exploits/50806
Product product
Official Product Homepage
https://www.malwarebytes.com/
Product product
Product Reference
https://www.malwarebytes.com/mwb-download/
Third Party Advisory third-party-advisory
VulnCheck Advisory: Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
https://www.vulncheck.com/advisories/malwarebytes-unquoted-service-path-privilege-escalation

Scores

CVSS v3 7.8
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-428
Status published
Products (1)
Malwarebytes/Malwarebytes 4.5.0
Published Jun 19, 2026
Tracked Since Jun 19, 2026