📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

Malwarebytes 5.4.4.225

Latest tracked version 5.4.4.225. Release status, tracked CVEs, and automated cross-platform patching for Malwarebytes.

PlatformLatest versionCVEs trackedLast checked
Windows5.4.4.225172024-05-23

Known vulnerabilities (CVEs) in Malwarebytes

Lavawall tracks 17 published CVEs affecting Malwarebytes, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2023-291472023-06-30 21:15:09MEDIUM (6)In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier.LOCAL
CVE-2023-291452023-06-30 20:15:09HIGH (8)The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger.LOCAL
CVE-2023-291442025-12-12 17:15:44LOW (3)Malwarebytes 1.0.14 for Linux doesn't properly compute signatures in some scenarios. This allows a bypass of detection.LOCAL
CVE-2023-260882023-03-23 01:15:12HIGH (8)In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios.LOCAL
CVE-2022-509712026-06-19 15:16:35HIGH (9)Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during service startup or system reboot.LOCAL
CVE-2020-286412020-12-22 23:15:13HIGH (7)In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system.LOCAL
CVE-2020-255332021-01-15 22:15:13HIGH (7)An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct a situation where the same PID is used for running two different programs at different times, by leveraging a race condition during crafted use of posix_spawn.LOCAL
CVE-2018-52792018-01-08 05:29:01MEDIUM (8)In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e02c. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).LOCAL
CVE-2018-52782018-01-08 05:29:01LOW (3)In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e00c. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).LOCAL
CVE-2018-52772018-01-08 05:29:01MEDIUM (6)In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e000. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).LOCAL
CVE-2018-52762018-01-08 05:29:01MEDIUM (6)In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e018. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).LOCAL
CVE-2018-52752018-01-08 05:29:01MEDIUM (6)In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E020. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).LOCAL
CVE-2018-52742018-01-08 05:29:01MEDIUM (6)In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E024. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).LOCAL
CVE-2018-52732018-01-08 05:29:01MEDIUM (6)In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e014. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).LOCAL
CVE-2018-52722018-01-08 05:29:00MEDIUM (6)In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e004. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).LOCAL
CVE-2018-52712018-01-08 05:29:00MEDIUM (6)In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e008. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).LOCAL
CVE-2018-52702018-01-08 05:29:00MEDIUM (8)In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e010. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).LOCAL

Why keeping Malwarebytes patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Malwarebytes release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches Malwarebytes

Lavawall® watches Malwarebytes releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Malwarebytes, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of Malwarebytes?
Lavawall tracks Malwarebytes at version 5.4.4.225 (last checked 2024-05-23). New releases are monitored continuously and can be deployed automatically across your fleet.
Does Malwarebytes have known security vulnerabilities (CVEs)?
Lavawall tracks 17 CVEs for Malwarebytes and remediates them automatically as part of patching.
How do I patch Malwarebytes automatically?
Deploy the Lavawall® agent and Malwarebytes updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for Malwarebytes through public information and proprietary statistical analysis, and can patch it automatically across your fleet.