CVE-2023-36631
Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Lack of access control in wfc.exe in Malwarebytes Binisoft Windows Firewall Control 6.9.2.0 allows local unprivileged users to bypass Windows Firewall restrictions via the user interface's rules tab. NOTE: the vendor's perspective is "this is intended behavior as the application can be locked using a password."
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.68% probability · 50th percentile
- CISA KEV
- Not listed
- Affected
- malwarebytes/binisoft windows firewall control
- Source
- cve@mitre.org
References
- https://hackerone.com/reports/2000375Permissions Required
- https://www.bencteux.fr/posts/malwarebytes_wfc/Exploit
- https://hackerone.com/reports/2000375Permissions Required
- https://www.bencteux.fr/posts/malwarebytes_wfc/Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.