
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-29144 is a detection bypass vulnerability in the Malwarebytes Endpoint Agent caused by improper signature computation. It affects Malwarebytes Endpoint Agent for Linux before version 1.1.64 and Malwarebytes for Windows v5 with an update package version below 1.0.104841. The vulnerability was publicly disclosed on December 12, 2025, with a patch advisory published by Malwarebytes. The CVSS v3.1 base score is listed as 3.3 (Low) in NVD, though Malwarebytes' own advisory assigns a score of 7.5 (High) (Malwarebytes Advisory, Red Hat CVE).
The root cause is classified as CWE-190 (Integer Overflow or Wraparound), where the Malwarebytes Endpoint Agent fails to properly compute signatures in certain scenarios due to an integer overflow condition. This flaw allows a local attacker with low privileges to craft inputs that cause the signature computation to produce incorrect results, effectively bypassing malware detection logic. The vulnerability requires local access and low privileges, with no user interaction needed. The vulnerability was discovered and credited to X41-Dsec (Malwarebytes Advisory).
Successful exploitation allows a local attacker to bypass the malware detection mechanisms of the Malwarebytes Endpoint Agent on both Linux and Windows platforms. This could enable malicious actors to introduce or execute malware on an endpoint without triggering security alerts, undermining the integrity of endpoint protection. The primary impact is on integrity (allowing undetected malicious activity), with no direct confidentiality or availability impact reported (Malwarebytes Advisory, Red Hat CVE).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires local access with low privileges, which limits the attack surface compared to remotely exploitable flaws. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Malwarebytes Advisory).
Malwarebytes has released patched versions addressing this vulnerability. Affected users should upgrade to Endpoint Agent for Linux version 1.1.64 or later, and Malwarebytes for Windows v5 to version 5.3.0.186 or later (update package version 1.0.104841 or later). No configuration-based workaround is available; upgrading to the patched version is the recommended and only mitigation. Additionally, restricting local user privileges and implementing supplementary endpoint detection and response (EDR) layers can reduce risk exposure (Malwarebytes Advisory).
The vulnerability was credited to security research firm X41-Dsec in the official Malwarebytes advisory. Community discussion has been limited, with mentions appearing on vulnerability tracking platforms and social media aggregators shortly after disclosure. No significant media coverage or notable researcher commentary beyond the vendor advisory has been identified (Malwarebytes Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."