Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.805402
Categoría:General
Título:Malwarebytes-Anti-Malware 'Upgrade' Man-In-The-Middle Attack (Windows)
Resumen:This host is installed with Malwarebytes; Anti-Malware and is prone to man in the middle attack through it's upgrade; functionality.
Descripción:Summary:
This host is installed with Malwarebytes
Anti-Malware and is prone to man in the middle attack through it's upgrade
functionality.

Vulnerability Insight:
MBAM client does not verify the actual
installer it downloads. This is combined with the fact that MBAM starts the
new client installer with full administrative privileges.

Vulnerability Impact:
Successful exploitation will allow
remote attackers to execute arbitrary code by spoofing the update server
and uploading an executable.

Affected Software/OS:
Malwarebytes Anti-Malware
(MBAM) Consumer versions before 2.0.3 on Windows

Solution:
Upgrade to version 2.0.3 or
later.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2014-4936
http://blog.0x3a.com/post/104954032239/cve-2014-4936-malwarebytes-anti-malware-and
http://packetstormsecurity.com/files/130244/Malwarebytes-Anti-Malware-Anti-Exploit-Update-Remote-Code-Execution.html
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.