Vulnerability Description
An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Malwarebytes | Adwcleaner | < 8.0.1 |
Related Weaknesses (CWE)
References
- https://borncity.com/win/2019/12/19/adwcleaner-8-0-1-closes-a-dll-hijacking-vulnVendor Advisory
- https://forums.malwarebytes.com/topic/254898-release-adwcleaner-801/Vendor Advisory
- https://www.bleepingcomputer.com/news/software/adwcleaner-801-fixes-dll-hijackinThird Party Advisory
- https://borncity.com/win/2019/12/19/adwcleaner-8-0-1-closes-a-dll-hijacking-vulnVendor Advisory
- https://forums.malwarebytes.com/topic/254898-release-adwcleaner-801/Vendor Advisory
- https://www.bleepingcomputer.com/news/software/adwcleaner-801-fixes-dll-hijackinThird Party Advisory
FAQ
What is CVE-2019-19929?
CVE-2019-19929 is a vulnerability with a CVSS score of 7.8 (HIGH). An Untrusted Search Path vulnerability in Malwarebytes AdwCleaner before 8.0.1 could cause arbitrary code execution with SYSTEM privileges when a malicious DLL library is loaded by the product.
How severe is CVE-2019-19929?
CVE-2019-19929 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19929?
Check the references section above for vendor advisories and patch information. Affected products include: Malwarebytes Adwcleaner.