CVE-2020-9363
Sophos Endpoint Anti-virus vulnerability analysis and mitigation

Overview

The Sophos AV parsing engine before 2020-01-14 contained a vulnerability that allows virus-detection bypass through specifically crafted ZIP archives. This vulnerability, tracked as CVE-2020-9363, affects multiple Sophos products including Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web Gateway (Zoller Blog).

Technical details

The vulnerability exists in the ZIP archive parsing functionality of the Sophos antivirus engine. The parsing engine can be bypassed by specifically manipulating a ZIP archive in a way that allows end-user access while evading antivirus scanning. When exploited, the AV engine is unable to scan the container and incorrectly assigns it a 'clean' rating (Zoller Blog).

Impact

The impact varies depending on the contextual use of the product and engine within an organization. Gateway products (Email, HTTP Proxy) may allow malicious files through unscanned while marking them as clean. Server-side AV software becomes unable to discover any malicious code or samples contained within the ZIP file, potentially allowing malware to evade detection (Zoller Blog).

Mitigation and workarounds

Sophos addressed this vulnerability with a patch deployed across their customer base on January 14, 2020. Users should ensure their Sophos products are updated to versions released after this date (Zoller Blog).

Additional resources


SourceThis report was generated using AI

Related Sophos Endpoint Anti-virus vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-8885HIGH8.8
  • Sophos Endpoint Anti-virusSophos Endpoint Anti-virus
  • cpe:2.3:a:sophos:intercept_x
NoYesOct 02, 2024
CVE-2020-9363HIGH7.8
  • Sophos Endpoint Anti-virusSophos Endpoint Anti-virus
  • cpe:2.3:a:sophos:endpoint_protection
NoYesFeb 24, 2020
CVE-2018-9233HIGH7.8
  • Sophos Endpoint Anti-virusSophos Endpoint Anti-virus
  • cpe:2.3:a:sophos:endpoint_protection
NoNoApr 05, 2018
CVE-2021-25264MEDIUM6.7
  • Sophos Endpoint Anti-virusSophos Endpoint Anti-virus
  • cpe:2.3:a:sophos:intercept_x
NoYesMay 17, 2021
CVE-2021-25266LOW3.9
  • NixOSNixOS
  • authenticator
NoYesApr 27, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management