CVE-2021-25269: Medium severity sophos exploit prevention vulnerability
A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25269?
CVE-2021-25269 is an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.
How can a local administrator exploit CVE-2021-25269?
A local administrator can exploit CVE-2021-25269 to prevent the HMPA service from starting despite tamper protection.
What is the severity of CVE-2021-25269?
CVE-2021-25269 has a severity rating of 4.4 (Medium).
Which software versions are affected by CVE-2021-25269?
Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server versions before 2.0.23, as well as Sophos Exploit Prevention versions before 3.8.3 are affected by CVE-2021-25269.
How can I fix CVE-2021-25269?
Update Sophos Intercept X Advanced, Sophos Intercept X Advanced for Server, and Sophos Exploit Prevention to version 2.0.23 or higher.