Vulnerability Description
Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Malwarebytes | Adwcleaner | <= 8.4.0 |
Related Weaknesses (CWE)
References
- https://forums.malwarebytes.com/topic/307429-release-adwcleaner-841/
- https://malwarebytes.comProduct
- https://www.malwarebytes.com/secure/cves/cve-2023-28892Vendor Advisory
- https://forums.malwarebytes.com/topic/307429-release-adwcleaner-841/
- https://malwarebytes.comProduct
- https://www.malwarebytes.com/secure/cves/cve-2023-28892Vendor Advisory
FAQ
What is CVE-2023-28892?
CVE-2023-28892 is a vulnerability with a CVSS score of 7.8 (HIGH). Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:\AdwCleaner\Logs\AdwCleaner_Debug.log in which the target location is user-controllable, allowin...
How severe is CVE-2023-28892?
CVE-2023-28892 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28892?
Check the references section above for vendor advisories and patch information. Affected products include: Malwarebytes Adwcleaner.