CVE-2023-29144
Homebrew vulnerability analysis and mitigation

Overview

CVE-2023-29144 is a detection bypass vulnerability in the Malwarebytes Endpoint Agent caused by improper signature computation. It affects Malwarebytes Endpoint Agent for Linux before version 1.1.64 and Malwarebytes for Windows v5 with an update package version below 1.0.104841. The vulnerability was publicly disclosed on December 12, 2025, with a patch advisory published by Malwarebytes. The CVSS v3.1 base score is listed as 3.3 (Low) in NVD, though Malwarebytes' own advisory assigns a score of 7.5 (High) (Malwarebytes Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-190 (Integer Overflow or Wraparound), where the Malwarebytes Endpoint Agent fails to properly compute signatures in certain scenarios due to an integer overflow condition. This flaw allows a local attacker with low privileges to craft inputs that cause the signature computation to produce incorrect results, effectively bypassing malware detection logic. The vulnerability requires local access and low privileges, with no user interaction needed. The vulnerability was discovered and credited to X41-Dsec (Malwarebytes Advisory).

Impact

Successful exploitation allows a local attacker to bypass the malware detection mechanisms of the Malwarebytes Endpoint Agent on both Linux and Windows platforms. This could enable malicious actors to introduce or execute malware on an endpoint without triggering security alerts, undermining the integrity of endpoint protection. The primary impact is on integrity (allowing undetected malicious activity), with no direct confidentiality or availability impact reported (Malwarebytes Advisory, Red Hat CVE).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability requires local access with low privileges, which limits the attack surface compared to remotely exploitable flaws. The EPSS score is approximately 0.012% (0.000120), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Malwarebytes Advisory).

Mitigation and workarounds

Malwarebytes has released patched versions addressing this vulnerability. Affected users should upgrade to Endpoint Agent for Linux version 1.1.64 or later, and Malwarebytes for Windows v5 to version 5.3.0.186 or later (update package version 1.0.104841 or later). No configuration-based workaround is available; upgrading to the patched version is the recommended and only mitigation. Additionally, restricting local user privileges and implementing supplementary endpoint detection and response (EDR) layers can reduce risk exposure (Malwarebytes Advisory).

Community reactions

The vulnerability was credited to security research firm X41-Dsec in the official Malwarebytes advisory. Community discussion has been limited, with mentions appearing on vulnerability tracking platforms and social media aggregators shortly after disclosure. No significant media coverage or notable researcher commentary beyond the vendor advisory has been identified (Malwarebytes Advisory).

Additional resources


SourceThis report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-72898CRITICAL10
  • NixOS logoNixOS
  • metabase
YesYesAug 10, 2026
CVE-2026-68968HIGH7.5
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util-odbc
NoYesAug 06, 2026
CVE-2026-68971MEDIUM6.5
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026
CVE-2026-68969MEDIUM6.5
  • Homebrew logoHomebrew
  • airflow
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management