CVE-2022-50971 PUBLISHED

Malwarebytes 4.5 Unquoted Service Path Privilege Escalation

Assigner: VulnCheck
Reserved: 11.01.2026 Published: 19.06.2026 Updated: 19.06.2026

Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during service startup or system reboot.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Malwarebytes
Product Malwarebytes
Versions
  • Version 4.5.0 is affected

Credits

  • Hejap Zairy finder

References

Problem Types

  • Unquoted Search Path or Element CWE