These are the release notes for Sophos Endpoint Security and Control for Windows Recommended versions, managed by Sophos Enterprise Console or standalone.
Some of the features mentioned in these release notes are only available on managed computers or if you have the appropriate license.
You may find that you can't yet download and use the latest version on the lists below. This is because Sophos releases the software over a number of days, but publishes the release notes on the first day.
You can find information on earlier releases, for up to the last two years, at Earlier releases.
You can find the product documentation here, Sophos Endpoint Security and Control.
Threat Detection Engine is updated to version 3.87.0.
Sophos Endpoint Security and Control | 10.8.14.1 VE3.87.0 January 2023 |
10.8.14.1 VE3.85.1 August 2022 |
10.8.14 VE3.85.1 April 2022 |
10.8.13 VE3.84.0 January 2022 |
10.8.12 VE 3.83.3 November 2021 |
10.8.11 VE 3.82.1 updated August 2021 |
10.8.11 VE 3.82.1 June 2021 |
10.8.11 VE 3.82.0 April 2021 |
10.8.10.1 VE 3.80.1 February 2021 |
10.8.9.2 VE 3.79.0 October 2020 |
10.8.9.1 VE 3.79.0 August 2020 |
---|---|---|---|---|---|---|---|---|---|---|---|
Sophos Anti-Virus | 10.8.14.9 | 10.8.14.9 | 10.8.14.9 | 10.8.13.42 | 10.8.12.23 | 10.8.11.22 | 10.8.11.22 | 10.8.11.22 | 10.8.10.810 | 10.8.9.610 | 10.8.9.292 |
Threat detection engine | 3.87.0 | 3.85.1 | 3.85.1 | 3.84.0 | 3.83.3 | 3.82.1 | 3.82.1 | 3.82.0 | 3.80.1 | 3.79.0 | 3.79.0 |
Sophos Client Firewall Windows 8 and later |
1.0.0.28 (stub) | 3.0.6 | 3.0.6 | 3.0.6 | 3.0.6 | 3.0.6 | |||||
Sophos Client Firewall Windows 7 and earlier |
1.0.0.28 (stub) | 2.9.7 | 2.9.7 | 2.9.7 | 2.9.7 | 2.9.7 | |||||
Sophos AutoUpdate | 5.18.10 | 5.18.10 | 5.18.10 | 5.17.243 | 5.17.243 | 5.17.243 | 5.17.243 | 5.17.243 | 5.17.243 | 5.16.37 | 5.16.37 |
Sophos Patch Agent | 1.0.0.28 (stub) | 1.0.313.30 | 1.0.313.30 | 1.0.313.30 | 1.0.313.30 | 1.0.313.30 | |||||
Sophos Web Control | 1.7.20 | 1.7.20 | 1.7.20 | 1.7.20 | 1.7.20 | 1.7.20 | 1.7.20 | 1.7.20 | 1.7.20 | 1.7.20 | 1.5 |
Sophos Remote Management System | 4.1.4.26 | 4.1.4.26 | 4.1.3.542 | 4.1.3.542 | 4.1.3.542 | 4.1.2.24 | 4.1.2.24 | 4.1.2.24 | 4.1.2.24 | 4.1.2.24 | 4.1.2.24 |
Sophos Network Threat Protection Malicious Traffic Detector |
1.9.2235 | 1.9.2235 | 1.9.2235 | 1.9.2235 | 1.9.2235 | 1.9.2235 | 1.9.2235 | 1.9.2235 | 1.9.2235 | 1.9.2235 | 1.9.2235 |
Sophos Endpoint Defense | 2.2.6.8739 | 2.2.6.8739 | 2.2.6.8739 | 2.2.6.8739 | 2.2.6.8739 | 2.2.6.8739 | 2.2.6.8672 | 2.2.6.8672 | 2.2.6.8672 | 2.2.4.8250 | 2.2.4.8250 |
Sophos Remote Management System is updated to version 4.1.4.26.
Sophos Anti-Virus is updated to version 10.8.14.9.
Sophos AutoUpdate is updated to version 5.18.10.
Threat Detection Engine is updated to version 3.85.1.
Sophos Anti-Virus is updated to version 10.8.13.42.
Threat Detection Engine is updated to version 3.84.0.
Issue ID | Component | Description |
---|---|---|
WINEP-37281 | Sophos Web Control | Resolved an issue where Web protection and control didn't work with Firefox version 94 and later. |
Sophos Anti-Virus is updated to version 10.8.12.23.
Sophos Remote Management System is updated to version 4.1.3.542.
Threat Detection Engine is updated to version 3.83.3.
Security enhancements and efficiency improvements.
The Sophos Client Firewall and Sophos Patch Agent components are now retired. They have been replaced by stub components.
Sophos Endpoint Defense is updated to version 2.2.6.8739.
Issue ID | Component | Description |
---|---|---|
WINEP-34794 | Sophos Endpoint Defense | Blocked from taking remediation steps in Safe Mode by Tamper Protection. |
Threat detection engine has been updated to 3.82.1.
Sophos Anti-Virus has been updated to 10.8.11.22.
Threat detection engine has been updated to 3.82.0.
Issue ID | Component | Description |
---|---|---|
WINEP-30513 | Sophos AntiVirus | Resolved an issue where Sophos AntiVirus stopped BeyondTrust PowerBroker applying its identity rules on Windows 10. |
Sophos Anti-Virus has been updated to 10.8.10.810.
Sophos AutoUpdate has been updated to 5.17.243.
Threat detection engine has been updated to 3.80.1.
Sophos Endpoint Defence has been updated to 2.2.6.8672.
Issue ID | Component | Description |
---|---|---|
WINEP-24935 | Sophos AutoUpdate | Resolved an authentication issue that stopped Sophos Anti-Virus updating. |
WINEP-27363 | Sophos Anti-Virus | Resolved an issue with Real Time Protection messages being sent when a machine restarts. |
Sophos Anti-Virus has been updated to 10.8.9.610.
Sophos Web Control has been updated to 1.7.20.
This release contains various fixes and updates.
This release includes support for the Vivaldi browser, including web protection, web control, download reputation, and data leakage prevention.
This release includes data leakage prevention support for computers with secure boot turned on.
Kanguru Defender Elite200 and IronKey D300S have been added to the list of secure devices in device control.
Sophos Anti-Virus has been updated to support %public% as an environment variable in file, folder, or process exclusions.
Sophos Anti-Virus has been updated to 10.8.9.292.
Sophos AutoUpdate has been updated to 5.16.37.
Sophos Network Threat Protection has been updated to 1.9.2235.
Sophos Endpoint Defense has been updated to 2.2.4.8250.
Issue ID | Component | Description |
---|---|---|
WINEP-9227 | Sophos Anti-Virus | Resolved an issue in which Windows stops unexpectedly on computers that have upgraded to Sophos Anti-Virus 10.6.4 and have IBM Clear Case installed. |
WINEP-11677 | Sophos Anti-Virus | Resolved an issue on Windows 10 or Server 2016 in which the text on the Messaging tab of the application control policy is truncated. |
WINEP-20496 | Sophos Web Control | Resolved an issue in which an upgrade could fail leaving protection disabled. |
WINEP-18719 | Sophos Anti-Virus | Resolved an issue in which Windows stops unexpectedly. Related to scanning files on network shares in the process of being modified by certain co-existing products. |
WINEP-16468 | Sophos Anti-Virus | Resolved an issue in which an internal on-access driver error 112 is logged when the user tries to upload .cab files to an FTP server using a batch file. |
WINEP-21052 | Sophos Anti-Virus | Resolved an issue in which Windows stops unexpectedly with a WIN32K_POWER_WATCHDOG_TIMEOUT error on laptops when changing between power states. |
WINEP-22138 | Sophos Anti-Virus | Resolved an issue in which Windows stops unexpectedly when the kernel stack has been exhausted |
WINEP-17474 | Sophos Anti-Virus | Resolved an issue in which data loss prevention checks are not suppressed while File Open and File Save dialog boxes are open. |
WINEP-16651 | Sophos Anti-Virus | Resolved an issue with Web Protection failures on Citrix servers when they are under load. |
WINEP-13785 | Sophos Endpoint Security and Control | Resolved data loss prevention issues with file creation on USB drive, file transfer, and Microsoft Outlook attachments on Windows 7 and 10. |
WINEP-15728 | Sophos Anti-Virus | Resolved an issue in which a file transfer is unexpectedly blocked by data control on an NTFS stream. |
WINEP-19087 | Sophos Anti-Virus | Resolved an issue on Windows Server 2016 in which browsing to some web sites is blocked by data control. |
WINEP-15982 | Sophos Anti-Virus | Resolved an issue in which Sophos Anti-Virus installation fails because of a failure in CreateUserGroups. |
WINEP-21543 | Sophos Anti-Virus | Resolved an issue with Sophos Anti-Virus integration with the Windows security center. |
The threat detection engine has been updated from 3.74.1 to 3.77.1.
Sophos AutoUpdate has been updated to 5.15.166.
Issue ID | Component | Description |
---|---|---|
WINEP-12971 | Sophos AutoUpdate | Resolved an issue with Sophos Anti-Virus failing to update. |
WINEP-16773 | Sophos AutoUpdate | Resolved an issue with unlocking computers with an identity agent installed if Almon.exe is running. |
WINEP-17442 | Sophos AutoUpdate | License expiry message is now available in all languages. |
Sophos Anti-Virus has been updated to 10.8.4.227.
Sophos Patch Agent has been updated to 1.0.313.30.
Sophos Remote Management Service has been updated to 4.1.2.24.
Sophos Network Threat Protection has been updated to 1.8.77.8000.
Sophos Endpoint Defense has been updated to 2.1.2.
Sophos System Protection (SSP) has been removed.
Custom installation paths are no longer supported. Existing installations using custom installation paths will fail to update to 10.8.4 and later versions.
A custom installation path is no longer offered by the standalone installer.
If you are upgrading from the previous version (10.8.2), the download size is 167MB.
If you are also subscribed to Sophos Patch Agent, the download size is an extra 21.2MB.
Issue ID | Component | Description |
---|---|---|
WINEP-7792 | Sophos Anti-Virus | Resolved an issue causing excessive CPU usage when opening the Sophos Anti-Virus GUI. |
WINEP-14732 | Sophos Anti-Virus | Resolved an issue generating false behavior detection log entries. |
WINEP-13683 | Sophos Anti-Virus | Resolved a resource leak seen with EPP in some configurations. |
WINEP-13879 | Sophos Anti-Virus | Resolved issue preventing migration to Sophos Central. |
WINEP-14543 | Sophos Remote Management System | Resolved an issue where message relay settings were lost. |
WINEP-12731 | Sophos Remote Management System | Resolved issue with communications to Sophos Enterprise Console on startup. |
WINEP-11298 | Sophos Network Threat Protection
Malicious Traffic Detector |
Resolved performance slowdown seen with MTD and SCF active. |
This update doesn't require a reboot.
Sophos Anti-Virus has been updated to 10.8.2.363.
Issue ID | Component | Description |
---|---|---|
WINEP-19220 | Sophos Anti-Virus | Resolved an issue with Microsoft updates causing machines to stop when starting. |
Component | Issue ID | Description | Comment |
---|---|---|---|
Sophos Anti-Virus | WINEP-1862 | If you have a version of Sophos Anti-Virus installed that is earlier than
10.3.15, and choose to uninstall it from the Windows 10
Setup wizard, What needs your attention screen by using the Uninstall button,
not all of the Sophos Endpoint Security and Control components will be
removed.
We recommend that you upgrade to Sophos Endpoint Security and Control 10.3.15 before upgrading to Windows 10. For more information about removing Sophos Endpoint Security and Control, see knowledgebase article 12360. |
Windows 10 support |
Sophos Anti-Virus | - | On 64-bit computers upgraded from Windows 8.1 to Windows 10, in the 32-bit
version of Windows Explorer, the right-click option Scan with Sophos
Anti-Virus does not work. (The option works correctly in the native 64-bit
version of Windows Explorer.) This is due to a missing Sophos registry key, that
has not been migrated during the OS upgrade.
To resolve this issue, re-protect the computers: in Sophos Enterprise Console, select the computers you want to re-protect, right-click, and then click Protect Computers. Follow the steps in the Protect Computers Wizard. Alternatively, to manually re-protect a computer, follow the steps provided in knowledgebase article 12386. |
V.10.3.15, Windows 10 support |
Sophos Anti-Virus | - | After an upgrade from Windows 8.1 (either 64-bit or 32-bit) to Windows 10, if a
computer is started in safe mode, the Sophos Anti-Virus service (SAVService.exe)
fails to start. This is due to a missing Sophos registry key, that has not been
migrated during the OS upgrade.
To resolve this issue, re-protect the computers. |
V.10.3.15, Windows 10 support |
Sophos Anti-Virus | - | After an upgrade from Windows 8.1 (either 64-bit or 32-bit) to Windows 10, the
Sophos Healthcheck tool fails
with warnings about missing registry keys. This
is because some of the Sophos registry keys have not been migrated during the OS
upgrade.
To resolve this issue, re-protect the computers. |
V.10.3.15, Windows 10 support |
Sophos Anti-Virus | WINEP-1813 | When upgrading Sophos Anti-Virus, for example, from 10.3.12 to 10.3.15, the
following error may appear in Sophos Enterprise Consoleand in the Sophos
Anti-Viruslog
on the endpoint:
Web protection is no longer functional. The filtering driver has been bypassed or unloaded 0xa058000c This issue is caused by Sophos Client Firewall blocking the web protection processes. To work around it, allow the processes in the firewall policy in Sophos Enterprise Consoleas follows. In the advanced Firewall Policy configuration dialog, under Configurations, click Configure next to a location you want to configure, go to the Processes tab, click Add to allow an application to launch hidden processes and add the following files: swi_lspdiag.exe and swi_lspdiag64.exe. |
V.10.3.15 |
Sophos Anti-Virus | - | When a computer is upgraded to Windows 10, the following error may be reported
against it in Sophos Enterprise Console.
Web Protection is no longer functional. The filtering driver has been bypassed or unloaded. [0xa058000c] These errors can be safely ignored. To remove them from Sophos Enterprise Console, after the computer has been upgraded to Windows 10, right-click the computer, click Resolve Alerts and Errors, select the errors and click Acknowledge. |
V.10.3.15, Windows 10 support |
Sophos Anti-Virus | WINEP-1770 | Sophos Anti-Virus doesn’t support Hypervisor enforced Code Integrity introduced in the Enterprise lockdown mode. | V.10.3.15, Windows 10 support |
Sophos AutoUpdate | WINEP-1841 | The update log (C:\ProgramData\Sophos\AutoUpdate\logs\alc.log)
contains messages about “skipped” components that are not included in this
version of Sophos Endpoint Security and Control,
for example:
Installation of Sophos Network Threat Protection skipped Installation of Sophos System Protection skipped These messages can be safely ignored. |
|
Sophos Client Firewall | - | After upgrading to Windows 10 a computer with a standalone installation of
Sophos Endpoint Security and Control that includes Sophos Client Firewall, the
firewall configuration can't be aplied. The following errors are logged in the
firewall system log:
Failed to configure the firewall. Failed to update the filter rules, error 80004005. To resolve this issue, restart the computer. |
V.10.3.15, Windows 10 support |
Sophos Client Firewall | WINEP-1819 | After an upgrade from Windows 7 to Windows 10, the firewall Windows 7 driver
SCFNdis.sys is migrated but can't be loaded and
may cause a system error when the computer is booted.
To resolve this issue, browse to the folder C:\Windows\System32\drivers and delete the file SCFNdis.sys. |
V.10.3.15, Windows 10 support |
Sophos Client Firewall | - | When a computer is upgraded to Windows 10, the following errors may be reported
against it in Sophos Enterprise Console:
Failed to configure the firewall. Failed to update the filter rules, error 80004005. These errors can be safely ignored. To remove them from Sophos Enterprise Console, after the computer has been upgraded to Windows 10, right-click the computer, click Resolve Alerts and Errors, select the errors and click Acknowledge. |
V.10.3.15, Windows 10 support |
Sophos Client Firewall | - | It is not possible to deploy Sophos Anti-Virus and Sophos Client Firewall to a
Windows 10 endpoint at the same time from
Sophos Enterprise Console.
Workaround: Deploy Sophos Anti-Virus first, and then re-run the Protect Computers Wizard and deploy Sophos Client Firewall. |
Windows 10 support |
Sophos Client Firewall | - | On upgrade to Windows 10, Sophos Client Firewall loses all custom configuration
settings and reverts to the default settings. Custom configuration settings need
to be re-applied following
the upgrade.
|
V.10.3.15, Windows 10 support |
Sophos Client Firewall | WINEP-1758 | On Windows 10, a dual location firewall policy can't be applied to an endpoint
when both locations are visible (this includes VPN connections). The following
errors appear in the firewall system log:
Failed to configure the firewall Failed to update the filter rules error 80004005 Workaround: Disable configuration for a secondary location, or use Windows Firewall instead. |
Windows 10 support |
Sophos Patch Agent | WINEP-1818 | In Sophos Enterprise Console, in the Protect
Computers Wizard, Windows 10 is not listed in the list of platforms on which
patch is available, even though Sophos Patch Agent can be installed on Windows
10.
Even though Sophos Patch Agent will install on Windows 10, it is not currently supported on it and will not report missing patch information. |
Windows 10 support |
Data Control | DEF79180 | Files that breach a data control rule can still be transferred to a Windows 8 storage pool. | |
Installer | DEF84838 | Protecting Windows 8 or Windows Server 2012 computers that are in a workgroup
from
Sophos Enterprise Console 5.1 on Windows Server 2008 or Windows Server 2008 R2
fails with the errors "Failed to launch
setup.exe" and "2147942405".
For more information and instructions on how to enable deployment, see knowledge base article 118354. |
|
Sophos Anti-Virus | DEF84420 | If you use a browser's Windows 8 Modern UI application to access a malicious website, and you click the toast that Sophos Anti-Virus displays, the browser is minimized and the desktop is displayed instead. To switch back to the browser, press Alt+Tab. | |
Sophos Anti-Virus | DEF83463 | Although Sophos Anti-Virus can scan files that are locked during an on-demand scan, it can't perform cleanup successfully. | |
Sophos Anti-Virus | DEF79482 | iSCSI mount points can't be excluded from on-access scanning. | |
Sophos Anti-Virus, Sophos Web Control | - | Sophos web protection and web control use a Layered Service Provider (LSP) to intercept network traffic. If web protection or web control is turned on while an incompatible third-party LSP is running, system instability can occur. Therefore, if a third-party LSP that is known to be incompatible is already installed on the computer, the Sophos LSP is not installed. For more information, see knowledge base article 116241. |
Sophos Endpoint Security and Control is supported on Windows XP/2003/Vista/2008/7/8/2012/Windows 10. For a full list of system requirements, see System Requirements for Antivirus protection for Windows.
To find out which maintenance version of Sophos Endpoint Security and Control (for example, 10.3.7) is running on your computer:
Automatic deployment of Sophos Endpoint Security and Control to Windows 8 and Windows Server 2012 from Sophos Enterprise Console requires Sophos Enterprise Console 5.1 or later.
Automatic deployment of Sophos Endpoint Security and Control to Windows 8.1 and Windows Server 2012 R2 from Sophos Enterprise Console requires Sophos Enterprise Console 5.2.1 R2 or later.
If you are using Sophos Enterprise Console 5.0 or earlier, you can install the software by running the installer from a bootstrap location that contains a software subscription for version 10.3. For more information on manual installation, see knowledge base article 12386.
Interactive mode
Hidden process detection
Modified memory detection
Rawsocket applications (rawsockets are treated the same as other connections)
Non-stateful rules
The option Concurrent connections for TCP rules
The option Where the local port is equal to the remote port
When Sophos Anti-Virus detects a controlled application on a remote share, the alert always shows that the application was detected on the local computer.
Sophos Device Control does not block removable storage devices that are used as system drives, as this typically destabilizes the operating system.
When you install Sophos software, some Windows components that might also be used by non-Sophos software are also installed or upgraded:
Sophos software | Shared Windows components | File names | Versions | Date of inclusion with Sophos software |
---|---|---|---|---|
Sophos Anti-Virus | Microsoft XML Core Services | msxml4.dll | 4.30.2100.0 | September 2009 |
Sophos Anti-Virus | Microsoft XML Core Services | msxml4r.dll | 4.30.2100.0 | September 2009 |
Sophos Anti-Virus | ATL Library | atl90.dll | 9.0.30729.4148 | June 2013 |
Sophos Anti-Virus | Microsoft Visual C/C++ Runtime Libraries | msvcm90.dll | 9.0.30729.4148 | June 2013 |
Sophos Anti-Virus | Microsoft Visual C/C++ Runtime Libraries | msvcp90.dll | 9.0.30729.4148 | June 2013 |
Sophos Anti-Virus | Microsoft Visual C/C++ Runtime Libraries | msvcr90.dll | 9.0.30729.4148 | June 2013 |
Sophos Client Firewall 3.0 for Windows 8 | Microsoft XML Core Services | msxml4.dll | 4.30.2100.0 | June 2013 |
Sophos Client Firewall 3.0 for Windows 8 | Microsoft XML Core Services | msxml4r.dll | 4.30.2100.0 | June 2013 |
Sophos Client Firewall 3.0 for Windows 8 | Microsoft Visual C/C++ Runtime Libraries | msvcm90.dll | 9.0.30729.6161 | June 2013 |
Sophos Client Firewall 3.0 for Windows 8 | Microsoft Visual C/C++ Runtime Libraries | msvcp90.dll | 9.0.30729.6161 | June 2013 |
Sophos Client Firewall 3.0 for Windows 8 | Microsoft Visual C/C++ Runtime Libraries | msvcr90.dll | 9.0.30729.6161 | June 2013 |
Sophos Client Firewall 2.9 for Windows 7 and earlier | Microsoft XML Core Services | msxml4.dll | 4.30.2100.0 | September 2009 |
Sophos Client Firewall 2.9 for Windows 7 and earlier | Microsoft XML Core Services | msxml4r.dll | 4.30.2100.0 | September 2009 |
Sophos Client Firewall 2.9 for Windows 7 and earlier | Microsoft Visual C/C++ Runtime Libraries | msvcm90.dll | 9.0.30729.6161 | October 2013 |
Sophos Client Firewall 2.9 for Windows 7 and earlier | Microsoft Visual C/C++ Runtime Libraries | msvcp90.dll | 9.0.30729.6161 | October 2013 |
Sophos Client Firewall 2.9 for Windows 7 and earlier | Microsoft Visual C/C++ Runtime Libraries | msvcr90.dll | 9.0.30729.6161 | October 2013 |
You can find technical support for Sophos products in any of these ways:
Copyright © 2023 Sophos Limited. All rights reserved. No part of this publication may be reproduced, stored in a retrieval system, or transmitted, in any form or by any means, electronic, mechanical, photocopying, recording or otherwise unless you are either a valid licensee where the documentation can be reproduced in accordance with the license terms or you otherwise have the prior permission in writing of the copyright owner.
Sophos and Sophos Anti-Virus are registered trademarks of Sophos Limited and Sophos Group. All other product and company names mentioned are trademarks or registered trademarks of their respective owners.