Tamper Protection Bypass in Sophos Endpoint Protection 10.7
CVE-2018-4863
5.5MEDIUM
What is CVE-2018-4863?
Sophos Endpoint Protection 10.7 has a vulnerability that allows local users to circumvent its tamper protection mechanism. This can be achieved by deleting a specific registry key located at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense. This exploit enables unauthorized users to disable security features, undermining the effectiveness of the endpoint protection and potentially leading to further system compromises.