Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w2v5-vxvg-mqgh

Опубликовано: 17 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8.7

Описание

Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an attacker must create a file in a given folder path and intercept the application log file deletion flow.

Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an attacker must create a file in a given folder path and intercept the application log file deletion flow.

EPSS

Процентиль: 3%
0.00015
Низкий

8.7 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.7
nvd
3 месяца назад

Malwarebytes AdwCleaner before v.8.7.0 runs as Administrator and performs an insecure log file delete operation in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link, a related issue to CVE-2023-28892. To exploit this, an attacker must create a file in a given folder path and intercept the application log file deletion flow.

EPSS

Процентиль: 3%
0.00015
Низкий

8.7 High

CVSS3

Дефекты

CWE-269