Bypass Vulnerability in Malwarebytes EDR for Linux
CVE-2023-29147

5.5MEDIUM

Key Information:

Vendor
CVE Published:
30 June 2023

What is CVE-2023-29147?

The vulnerability in Malwarebytes EDR for Linux allows attackers to circumvent detection mechanisms reliant on inode identifiers. This occurs due to the possibility of identifier reuse when a file is replaced, as well as the occurrence of identical identifiers across different filesystems. Consequently, malicious files may evade detection, posing significant security risks to systems relying on this software.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.