Executive brief
Malwarebytes 4.5 is an antivirus and security software suite used to protect computers from malicious software. A vulnerability in how the software starts its background service allows a person with limited access to the computer to trick the system into running their own malicious code with full administrative control. This could lead to a complete takeover of the machine, allowing an attacker to bypass security settings or access sensitive data.
Technical details
An unquoted service path vulnerability (CWE-428) exists in the MBAMService executable within Malwarebytes version 4.5.0 and potentially earlier. The service's binary path contains spaces and is not enclosed in quotation marks, which allows a local attacker with write permissions to the system root or intermediate directories to place a malicious executable (e.g., C:\Program.exe). Because the service runs with LocalSystem privileges, the malicious file will be executed with elevated permissions during the next service start or system reboot. This is a local attack vector requiring prior access to the filesystem but no user interaction.
Affected products
- Malwarebytes Malwarebytes 4.5.0 and earlier
Timeline
- 2022-03-07: other: Exploit first published on Exploit-DB
- 2026-06-19: advisory: NVD/VulnCheck advisory published