Malwarebytes and Nebula Out-of-Bounds Read Vulnerability Leading to Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in Malwarebytes versions 4.6.14.326 and earlier, as well as in version 5.1.5.116 and earlier. This issue also affects the Nebula platform starting from the 2020-10-21 release. The vulnerability arises from an out-of-bounds read in several disassembling utilities, which causes stability issues and disrupts service.

Impact

Exploitation of this vulnerability leads to stability issues and a denial-of-service condition, causing the application to become unresponsive or unavailable.

Remediation

Users are advised to upgrade to Malwarebytes version 4.6.14.326 or later, version 5.1.5.116 or later, or to the Nebula platform version available in June 2024. For the Nebula Endpoint Agent, version 2.0.0.64 or later should be used, and for the Protection Service, version 4.6.17.334 or later is recommended.

Added: Aug 14, 2025, 4:52 PM
Updated: Aug 14, 2025, 4:52 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.