CVE-2014-100039: Malwarebytes Anti-Exploit

Low severity, CVSS 2.1. EPSS: 0.7% chance of exploitation in the next 30 days.

mbae.sys in Malwarebytes Anti-Exploit before 1.05.1.2014 allows local users to cause a denial of service (crash) via a crafted size in an unspecified IOCTL call, which triggers an out-of-bounds read. NOTE: some of these details are obtained from third party information.

Affected products

  • Malwarebytes Malwarebytes Anti-Exploit: up to and including 1.04.1.1012

Published 2015-01-13. Last modified 2026-06-17.