Patch & vulnerability status
Malwarebytes 5.4.4.225
Latest tracked version 5.4.4.225. Release status, tracked CVEs, and automated cross-platform patching for Malwarebytes.
| Platform | Latest version | CVEs tracked | Last checked |
|---|---|---|---|
| Windows | 5.4.4.225 | 17 | 2024-05-23 |
Known vulnerabilities (CVEs) in Malwarebytes
Lavawall tracks 17 published CVEs affecting Malwarebytes, and deploys the versions that fix them automatically across your fleet.
| CVE | Published | Severity | Details | Vector |
|---|---|---|---|---|
| CVE-2023-29147 | 2023-06-30 21:15:09 | MEDIUM (6) | In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier. | LOCAL |
| CVE-2023-29145 | 2023-06-30 20:15:09 | HIGH (8) | The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger. | LOCAL |
| CVE-2023-29144 | 2025-12-12 17:15:44 | LOW (3) | Malwarebytes 1.0.14 for Linux doesn't properly compute signatures in some scenarios. This allows a bypass of detection. | LOCAL |
| CVE-2023-26088 | 2023-03-23 01:15:12 | HIGH (8) | In Malwarebytes before 4.5.23, a symbolic link may be used delete any arbitrary file on the system by exploiting the local quarantine system. It can also lead to privilege escalation in certain scenarios. | LOCAL |
| CVE-2022-50971 | 2026-06-19 15:16:35 | HIGH (9) | Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during service startup or system reboot. | LOCAL |
| CVE-2020-28641 | 2020-12-22 23:15:13 | HIGH (7) | In Malwarebytes Free 4.1.0.56, a symbolic link may be used delete an arbitrary file on the system by exploiting the local quarantine system. | LOCAL |
| CVE-2020-25533 | 2021-01-15 22:15:13 | HIGH (7) | An issue was discovered in Malwarebytes before 4.0 on macOS. A malicious application was able to perform a privileged action within the Malwarebytes launch daemon. The privileged service improperly validated XPC connections by relying on the PID instead of the audit token. An attacker can construct a situation where the same PID is used for running two different programs at different times, by leveraging a race condition during crafted use of posix_spawn. | LOCAL |
| CVE-2018-5279 | 2018-01-08 05:29:01 | MEDIUM (8) | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e02c. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit). | LOCAL |
| CVE-2018-5278 | 2018-01-08 05:29:01 | LOW (3) | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e00c. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit). | LOCAL |
| CVE-2018-5277 | 2018-01-08 05:29:01 | MEDIUM (6) | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e000. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit). | LOCAL |
| CVE-2018-5276 | 2018-01-08 05:29:01 | MEDIUM (6) | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e018. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit). | LOCAL |
| CVE-2018-5275 | 2018-01-08 05:29:01 | MEDIUM (6) | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E020. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit). | LOCAL |
| CVE-2018-5274 | 2018-01-08 05:29:01 | MEDIUM (6) | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E024. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit). | LOCAL |
| CVE-2018-5273 | 2018-01-08 05:29:01 | MEDIUM (6) | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e014. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit). | LOCAL |
| CVE-2018-5272 | 2018-01-08 05:29:00 | MEDIUM (6) | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e004. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit). | LOCAL |
| CVE-2018-5271 | 2018-01-08 05:29:00 | MEDIUM (6) | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e008. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit). | LOCAL |
| CVE-2018-5270 | 2018-01-08 05:29:00 | MEDIUM (8) | In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e010. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit). | LOCAL |
Why keeping Malwarebytes patched matters
Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every Malwarebytes release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.
How Lavawall® patches Malwarebytes
Lavawall® watches Malwarebytes releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on Malwarebytes, one policy to bring them current, and timestamped evidence for audits.
Frequently asked questions
Lavawall tracks Malwarebytes at version 5.4.4.225 (last checked 2024-05-23). New releases are monitored continuously and can be deployed automatically across your fleet.
Lavawall tracks 17 CVEs for Malwarebytes and remediates them automatically as part of patching.
Deploy the Lavawall® agent and Malwarebytes updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.
Lavawall® monitors releases and CVEs for Malwarebytes through public information and proprietary statistical analysis, and can patch it automatically across your fleet.