CVE Vulnerabilities

CVE-2023-29145

Published: Jun 30, 2023 | Modified: Nov 26, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Malwarebytes EDR 1.0.11 for Linux driver doesnt properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger.

Affected Software

NameVendorStart VersionEnd Version
Endpoint_detection_and_responseMalwarebytes*1.0.11 (including)
MalwarebytesMalwarebytes*1.0.14 (including)

References