Malwarebytes is patching a memory corruption vulnerability discovered in antivirus software.
As researchers at COSIG (Government Governmental Informatics Security Operational Center) point out, this vulnerability affected the Windows and was successfully patched.
The vulnerability was discovered by Francis Provencher, a member of the research and pentesting team at COSIG, based in Canada. According to the researcher, the vulnerability is triggered “when a malicious executable containing an invalid integer (-1) in the “SizeOfRawData” of the UPX section is parsed by Malwarebytes antivirus. This leads to memory corruption on the user’s computer, which in turn exposes the system to situations where arbitrary code can be executed by an attacker who exploits the vulnerability.
Memory corruption occurs when the contents of a memory location are unintentionally modified by programming errors or malicious code, as in this case.
Mr. Provencher and COSIG responsibly disclosed the issue to Malwarebytes Corporation, the company behind MalwareBytes Anti-Malware (MBAM) antivirus.
[alert variation=”alert-success”]The code that demonstrates the vulnerability (proof of concept) is available on GitHub, but also through the Protek Research Lab website.[/alert]
"A vulnerability affecting Malwarebytes Anti-Malware 2.2.0 was reported to us by an independent researcher," a Malwarebytes spokesperson said. "A fix was released two days after the bug was reported, and there is no evidence to date that the vulnerability has been exploited in attacks. We work closely with external researchers, and we appreciate the opportunity to improve our products," he said.

