Description
An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encryption utilities.
Published: 2026-06-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap buffer overflow found in the buffer encryption utilities of Malwarebytes versions 4.x and 5.x and all Nebula releases from 2020‑10‑21 onward. It arises when the utilities process oversized or malformed data buffers, corrupting heap memory. This overflow can allow an attacker to overwrite arbitrary memory addresses, potentially leading to remote code execution, privilege escalation, or service disruption.

Affected Systems

Systems that run Malwarebytes 4.x or 5.x, or Nebula deployed from 2020‑10‑21 onward, are affected. The flaw exists in the encryption components that may handle data from external or untrusted sources, so any endpoint running these versions bears the risk.

Risk and Exploitability

The CVSS score of 7.5 classifies the flaw as high severity, indicating that exploitation could compromise confidentiality, integrity, or availability. The description does not specify an exact attack vector, but heap overflows are commonly triggered by malicious input fed to the encryption routine, which could be done locally or through a network‑based interface if present. Because the EPSS score is unavailable and the issue is not listed in the CISA KEV catalog, there is no evidence of widespread exploitation yet; however, the nature of the heap corruption means that a successful exploit could allow arbitrary code execution. Prompt patching and monitoring for abnormal process behavior remain prudent.

Generated by OpenCVE AI on June 10, 2026 at 00:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Malwarebytes Anti‑Malware to the latest 6.x release or upgrade Nebula to a version that contains the fix for the heap overflow; obtain the update from the vendor’s official website.
  • If an upgrade cannot be performed immediately, reconfigure the endpoint protection to disable or restrict the encryption utilities that handle external input, or enforce a policy that permits encryption only for data originating from trusted processes.
  • As a temporary hardening measure, enable operating‑system facilities such as ASLR and stack canaries, and run the Malwarebytes services under a least‑privilege user context to limit the impact of any potential overflow.

Generated by OpenCVE AI on June 10, 2026 at 00:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 10 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Malwarebytes
Malwarebytes malwarebytes
Vendors & Products Malwarebytes
Malwarebytes malwarebytes

Wed, 10 Jun 2026 00:45:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Malwarebytes Encryption Utilities

Tue, 09 Jun 2026 23:30:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Malwarebytes Encryption Utilities
Weaknesses CWE-119
CWE-120

Tue, 09 Jun 2026 21:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Malwarebytes Encryption Utilities
Weaknesses CWE-119
CWE-120

Tue, 09 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Jun 2026 18:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encryption utilities.
References

Subscriptions

Malwarebytes Malwarebytes
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-09T19:30:20.198Z

Reserved: 2023-09-21T00:00:00.000Z

Link: CVE-2023-43688

cve-icon Vulnrichment

Updated: 2026-06-09T19:30:04.857Z

cve-icon NVD

Status : Deferred

Published: 2026-06-09T19:16:42.060

Modified: 2026-06-09T21:17:01.950

Link: CVE-2023-43688

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-10T02:00:12Z

Weaknesses