Vulnerabilities > CVE-2018-4863 - 7PK - Security Features vulnerability in Sophos Endpoint Protection 10.7

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
local
low complexity
sophos
CWE-254
exploit available

Summary

Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.

Vulnerable Configurations

Part Description Count
Application
Sophos
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionSophos Endpoint Protection 10.7 - Tamper-Protection Bypass. CVE-2018-4863. Local exploit for Windows platform
fileexploits/windows/local/44410.txt
idEDB-ID:44410
last seen2018-05-24
modified2018-04-06
platformwindows
port
published2018-04-06
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44410/
titleSophos Endpoint Protection 10.7 - Tamper-Protection Bypass
typelocal

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/147039/SOPHOS-ENDPOINT-PROTECTION-v10.7-TAMPER-PROTECTION-BYPASS-CVE-2018-4863.txt
idPACKETSTORM:147039
last seen2018-04-05
published2018-04-04
reporterhyp3rlinx
sourcehttps://packetstormsecurity.com/files/147039/Sophos-Endpoint-Protection-10.7-Tamper-Protection-Bypass.html
titleSophos Endpoint Protection 10.7 Tamper Protection Bypass