Medium severity6.7NVD Advisory· Published May 17, 2021· Updated Jun 17, 2026
CVE-2021-25264
CVE-2021-25264
Description
In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.
Affected products
7cpe:2.3:a:sophos:intercept_x:*:*:*:*:central:macos:*:*+ 1 more
- cpe:2.3:a:sophos:intercept_x:*:*:*:*:central:macos:*:*range: <=10.0.3
- cpe:2.3:a:sophos:intercept_x:*:*:*:*:opm:macos:*:*range: <=9.10.1
- Sophos/Intercept X for MacOSv5Range: unspecified
- Sophos/Intercept X for MacOS (OPM)v5Range: unspecified
- Sophos/Sophos Home for MacOSv5Range: unspecified
Patches
Vulnerability mechanics
References
2- community.sophos.com/b/security-blognvdVendor Advisory
- community.sophos.com/b/security-blog/posts/resolved-lpe-in-endpoint-for-macos-cve-2021-25264nvdVendor Advisory
News mentions
0No linked articles in our index yet.