CVE-2021-25269

Severity CVSS v4.0:
Pending analysis
Type:
CWE-428 Unquoted Search Path or Element
Publication date:
26/11/2021
Last modified:
03/12/2021

Description

A local administrator could prevent the HMPA service from starting despite tamper protection using an unquoted service path vulnerability in the HMPA component of Sophos Intercept X Advanced and Sophos Intercept X Advanced for Server before version 2.0.23, as well as Sophos Exploit Prevention before version 3.8.3.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sophos:exploit_prevention:*:*:*:*:*:*:*:* 3.8.3 (excluding)
cpe:2.3:a:sophos:intercept_x_endpoint:*:*:*:*:*:*:*:* 2.0.23 (excluding)
cpe:2.3:a:sophos:intercept_x_for_server:*:*:*:*:*:*:*:* 2.0.23 (excluding)