CVE-2023-43692
7.5Malwarebytes · Multiple Products
Malwarebytes products contain an out-of-bounds read vulnerability in string detection utilities that can lead to system crashes.
Executive summary
A critical out-of-bounds read vulnerability in Malwarebytes products allows unauthenticated attackers to cause system instability and crashes.
Vulnerability
The vulnerability involves an out-of-bounds read within string detection utilities, which can be triggered by an unauthenticated attacker to force a system crash.
Business impact
Successful exploitation of this vulnerability results in a denial-of-service condition due to system crashes, impacting system availability and operational continuity. While the CVSS score of 7.5 reflects a high severity based on the ease of exploitation (AV:N/AC:L/PR:N/UI:N), the primary impact is limited to system availability rather than data confidentiality or integrity.
Remediation
Immediate Action: Update all affected Malwarebytes installations to the versions specified in the vendor advisory (4.6.14.326, 5.1.5.116, or the latest Nebula updates).
Proactive Monitoring: Monitor system event logs and crash reports for unexpected application terminations that may indicate exploitation attempts.
Compensating Controls: Ensure network traffic is inspected by an intrusion detection system to identify and block malformed packets directed at endpoint security agents.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for service disruption, administrators should prioritize updating Malwarebytes agents across the enterprise environment. Applying the provided security updates is the only definitive method to resolve this vulnerability and ensure continued system stability.