CVE-2023-29145

HIGH

Malwarebytes EDR <1.0.11 - RCE

Title source: llm
STIX 2.1

Description

The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger.

Scores

CVSS v3 7.8
EPSS 0.0009
EPSS Percentile 25.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-640
Status published
Products (2)
malwarebytes/endpoint_detection_and_response < 1.0.11
malwarebytes/malwarebytes < 1.0.14
Published Jun 30, 2023
Tracked Since Feb 18, 2026