CVE-2014-4936: Malwarebytes Anti-Exploit
High severity, CVSS 9.3. EPSS: 16.8% chance of exploitation in the next 30 days.
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE) consumer 1.04.1.1012 and earlier allow man-in-the-middle attackers to execute arbitrary code by spoofing the update server and uploading an executable.
Affected products
- Malwarebytes Malwarebytes Anti-Exploit: up to and including 1.04.1.1012
- Malwarebytes Malwarebytes Anti-Malware: up to and including 2.02
Published 2014-12-16. Last modified 2026-06-17.