Executive brief
A vulnerability in Malwarebytes and Nebula security software can allow a local user to cause a denial of service. By creating a large number of Firefox preference files, an attacker can overwhelm the software's parser, causing it to ignore other browser configuration files. This effectively disables certain security monitoring or configuration features, potentially leaving the system unprotected or causing the security application to malfunction.
Technical details
The vulnerability is classified as CWE-755 (Improper Handling of Exceptional Conditions) within the Malwarebytes and Nebula configuration parsing engine. A local attacker can trigger this issue by populating a system with an excessive number of Firefox preference files. This condition causes the parser to fail or skip the processing of other critical browser configuration files. The result is a denial of service (DoS) state for the affected security component, potentially bypassing local policy enforcement or monitoring. Patches have been released for Malwarebytes 4 (v4.6.14.326), Malwarebytes 5 (v5.1.5.116), and Nebula (Endpoint Agent v2.0.0.64).
Affected products
- Malwarebytes Malwarebytes 4.x < 4.6.14.326
- Malwarebytes Malwarebytes 5.x < 5.1.5.116
- Malwarebytes Nebula Endpoint Agent < 2.0.0.64, Protection Service < 4.6.17.334
Timeline
- 2026-06-09: advisory: NVD and Vendor advisory published