First published: Fri Nov 26 2021(Updated: )
A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.
Credit: security-alert@sophos.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sophos Exploit Prevention | <3.8.3 | |
Sophos Intercept X Endpoint | <2.0.23 | |
Sophos Intercept X For Server | <2.0.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-25269 is an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.
A local administrator can exploit CVE-2021-25269 to prevent the HMPA service from starting despite tamper protection.
CVE-2021-25269 has a severity rating of 4.4 (Medium).
Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server versions before 2.0.23, as well as Sophos Exploit Prevention versions before 3.8.3 are affected by CVE-2021-25269.
Update Sophos Intercept X Advanced, Sophos Intercept X Advanced for Server, and Sophos Exploit Prevention to version 2.0.23 or higher.