nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-50971 CVE-2022-50971
HIGH
Malwarebytes 4.5 Unquoted Service Path Privilege Escalation
Record summary
CVE-2022-50971 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during service startup or system reboot.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MalwarebytesBrowse Malwarebytes / Malwarebytes | CVE List | 4.5.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBMalwarebytes 4.5 - Unquoted Service PathExploitDB exploitby Hejap Zairy Al-SharifNot analyzed1 file
References
5ExploitDB-50806exploit
https://www.exploit-db.com/exploits/50806 Official Product Homepageproduct
https://www.malwarebytes.com/ Product Referenceproduct
https://www.malwarebytes.com/mwb-download VulnCheck Advisory: Malwarebytes 4.5 Unquoted Service Path Privilege EscalationThird-party advisory
https://www.vulncheck.com/advisories/malwarebytes-unquoted-service-path-privilege-escalation