コンテンツに移動
Informational

High

Resolved LPE in HitmanPro (CVE-2021-25271)

CVE(N)

CVE-2021-25271

PRODUCT(S)

HitmanPro

更新日

2021 Oct 7

記事バージョン

2

公開日

2021 Oct 7

公開 ID

sophos-sa-20211007-hmp-lpe

回避策

No

Overview

A local privilege escalation vulnerability in HitmanPro was discovered and responsibly disclosed to Sophos. It was reported via the Sophos bug bounty program by an external security researcher. The vulnerability has been fixed. There is no action required for customers, as updates are installed automatically by default.

Sophos would like to thank Michael Bourque (@downwithupsec) for responsibly disclosing the issues to Sophos.

The remediation prevented local users from reading or writing arbitrary files with administrator privileges. There was no evidence that the vulnerability was exploited and to our knowledge no customers are impacted.

Applies to the following Sophos product(s) and version(s)

  • Sophos HitmanPro prior version Build 318

The Sophos Intercept X family is not impacted by this advisory.

Remediation

  • Fix included in HitmanPro Build 318, released May 31, 2021

Related Information

Sophos Logo

Sophos Responsible Disclosure Policy

To learn about Sophos security vulnerability disclosure policies and publications, see the Responsible Disclosure Policy.