CVE-2018-4863: Sophos Endpoint Protection
Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.
Affected products
- Sophos Endpoint Protection: version 10.7 only
Published 2018-04-05. Last modified 2026-06-17.