CVE-2018-4863: Sophos Endpoint Protection

Medium severity, CVSS 5.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.

Affected products

  • Sophos Endpoint Protection: version 10.7 only

Published 2018-04-05. Last modified 2026-06-17.