CVE-2020-9363
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway. NOTE: the vendor feels that this does not apply to endpoint-protection products because the virus would be detected upon extraction.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.97% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-436
- Affected
- sophos/cloud optix · sophos/endpoint protection · sophos/intercept x endpoint · sophos/intercept x for server · sophos/mobile · sophos/secure web gateway
- Source
- cve@mitre.org
References
- https://blog.zoller.lu/p/release-mode-coordinated-disclosure-ref.htmlThird Party Advisory
- https://community.sophos.com/b/security-blog/posts/sophos-comments-to-cve-2020-9363Vendor Advisory
- https://blog.zoller.lu/p/release-mode-coordinated-disclosure-ref.htmlThird Party Advisory
- https://community.sophos.com/b/security-blog/posts/sophos-comments-to-cve-2020-9363Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.