Executive brief
A security vulnerability was identified in Malwarebytes and Nebula security software involving how the software handles encrypted data in memory. While the flaw could theoretically allow an attacker to disrupt the service or gain unauthorized access, the manufacturer states the risk is extremely low because the affected code was not included in the final software packages released to customers. Users are encouraged to update to the latest versions to ensure they are running the most secure and up-to-date code.
Technical details
A heap-based buffer overflow (CWE-122) was discovered in various buffer encryption utility functions within Malwarebytes 4.x, 5.x, and the Nebula platform (Endpoint Agent and Protection Service). The vulnerability stems from improper bounds checking during encryption operations. Although the vendor assigned a CVSS score of 7.5, they noted that the likelihood of exploitation is low because the specific affected utility functions were reportedly not included in the final released software packages. An attacker with local access could potentially exploit this to achieve arbitrary code execution or cause a denial-of-service condition. The issue has been addressed by removing the unused utility functions from the source code in the patched versions.
Affected products
- Malwarebytes Malwarebytes 4.x < 4.6.14.326
- Malwarebytes Malwarebytes 5.x < 5.1.5.116
- Malwarebytes Nebula Endpoint Agent < 2.0.0.64
- Malwarebytes Nebula Protection Service < 4.6.17.334
Timeline
- 2026-06-09: advisory: NVD and vendor advisory published