CVE-2018-4863
MEDIUMSophos Endpoint Protection 10.7 - Tamper Protection Bypass via Registry Key Deletion
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-4863. PoCs published by hyp3rlinx.
AI-analyzed exploit summary The exploit bypasses Sophos Endpoint Protection's tamper protection by deleting a critical registry key and rebooting the system, allowing arbitrary registry modifications. It leverages a simple C program to execute registry deletion and force a reboot.
Description
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.
Exploits (1)
The exploit bypasses Sophos Endpoint Protection's tamper protection by deleting a critical registry key and rebooting the system, allowing arbitrary registry modifications. It leverages a simple C program to execute registry deletion and force a reboot.
References (3)
Scores
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N