---
id: CVE-2022-50971
title: >-
  Malwarebytes 4.5 contains an unquoted service path vulnerability in the
  MBAMService executable that allows local attackers to escalate privileges by
  injecting malicious code into the system root path
summary: >-
  Malwarebytes 4.5 contains an unquoted service path vulnerability in the
  MBAMService executable that allows local attackers to escalate privileges by
  injecting malicious code into the system root path. Attackers can place
  executable files…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
vendor: malwarebytes
product: malwarebytes
affected:
  - malwarebytes <= 4.5.0
published: '2026-06-19'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T09:10:00.157'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-50971'
references:
  - url: 'https://www.exploit-db.com/exploits/50806'
    label: disclosure@vulncheck.com
  - url: 'https://www.malwarebytes.com/'
    label: disclosure@vulncheck.com
  - url: 'https://www.malwarebytes.com/mwb-download/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/malwarebytes-unquoted-service-path-privilege-escalation
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00225
epssPercentile: 0.1181
ingestedAt: '2026-09-29T09:30:49.077Z'
---

## Overview

Malwarebytes 4.5 contains an unquoted service path vulnerability in the MBAMService executable that allows local attackers to escalate privileges by injecting malicious code into the system root path. Attackers can place executable files in unquoted path directories that execute with LocalSystem privileges during service startup or system reboot.

## Affected

- `malwarebytes <= 4.5.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
