In Malwarebytes before 4.5.23, a symbolic link may be...
High severity
Unreviewed
Published
Mar 23, 2023
to the GitHub Advisory Database
•
Updated Apr 5, 2023
Description
Published by the National Vulnerability Database
Mar 23, 2023
Published to the GitHub Advisory Database
Mar 23, 2023
Last updated
Apr 5, 2023
In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.
References