CVE-2021-25264: High severity sophos home vulnerability
Published May 17, 2021
·Updated
In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.
Affected Software
3 affected components
Sophos Home Macos<=10.0.3
Sophos Intercept X Macos<=9.10.1
Sophos Intercept X Macos<=10.0.3
Event History
May 17, 2021
CVE Published
via MITRE·05:02 PM
Data Sourced
via MITRE·05:02 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-25264.
2
What is the severity of CVE-2021-25264?
The severity of CVE-2021-25264 is high with a severity value of 6.7.
3
Which Sophos Endpoint products for MacOS are affected?
Multiple versions of Sophos Home, Sophos Intercept X with OPM, and Sophos Intercept X with Central for MacOS are affected.
4
What can a local attacker do with CVE-2021-25264?
A local attacker could execute arbitrary code with administrator privileges.
5
How can I fix CVE-2021-25264?
Upgrade to the latest versions of the affected Sophos Endpoint products for MacOS.