What Are the Latest Sophos Intercept X for Windows Vulnerabilities and How Do They Enable Arbitrary Code Execution?
Three high-severity vulnerabilities—CVE-2024-13972, CVE-2025-7433, and CVE-2025-7472—have been discovered in Sophos Intercept X for Windows, allowing local attackers to gain system-level privileges and execute arbitrary code. These flaws affect the updater, Device Encryption, and Windows installer components. With no available workarounds, users must immediately update to the latest versions to mitigate risks of privilege escalation and system compromise.
Quick answer: Sophos Intercept X for Windows had three flaws, CVE-2024-13972, CVE-2025-7433 and CVE-2025-7472, in its updater, Device Encryption and installer components. A local attacker could escalate privileges and run code with system-level rights. Install the latest Sophos updates and confirm your version after patching.
Key takeaways
- The three flaws are CVE-2024-13972, CVE-2025-7433 and CVE-2025-7472 in the updater, Device Encryption and installer.
- Versions released before the 17 July 2025 patch update are affected.
- A local attacker could gain system-level rights, so install the latest Sophos update and confirm the version.
Table of Contents
- What Are the New Sophos Intercept X Vulnerabilities?
- Who Discovered These CVEs?
- How Do These Vulnerabilities Work?
- Which Versions Are Affected?
- What Is the Risk for Enterprises?
- Are There Any Workarounds?
- How to Apply the Fixes
- Where to Download the Latest Updates?
- Why Is Timely Patching Critical?
- How to Confirm You're Safe?
- Conclusion
Sophos Intercept X for Windows has recently been found vulnerable to three critical flaws that can lead to arbitrary code execution with system-level privileges. These vulnerabilities, CVE-2024-13972, CVE-2025-7433, and CVE-2025-7472, affect core components such as the updater, Device Encryption, and installer, putting enterprises at serious risk of privilege escalation attacks.
What Are the New Sophos Intercept X Vulnerabilities?
Researchers discovered three serious vulnerabilities in Sophos Intercept X for Windows that could allow a local attacker to escalate privileges and execute arbitrary code. The flaws were responsibly disclosed and have since been patched.
The vulnerabilities include:
-
Misconfigured registry permissions
-
Improper handling in the Device Encryption component
-
Insecure file permissions in the Windows installer
These weaknesses affect versions of Intercept X for Windows released before the latest patch update on July 17, 2025.
Who Discovered These CVEs?
The vulnerabilities were disclosed by trusted researchers through responsible channels:
-
CVE-2024-13972 – Discovered by Filip Dragovic (MDSec)
-
CVE-2025-7433 – Reported by Sina Kheirkhah via WatchTower
-
CVE-2025-7472 – Submitted by Sandro Poppi through Sophos’s bug bounty program
How Do These Vulnerabilities Work?
CVE-2024-13972: Registry ACL Vulnerability
The updater in Sophos Intercept X used overly permissive registry ACLs, allowing a non-privileged user to modify critical registry values during an update. This allows attackers to inject malicious code executed with SYSTEM privileges.
CVE-2025-7433: Device Encryption Component Flaw
This issue lies in the Central Device Encryption module, where authenticated local users can load unsigned or arbitrary code, effectively bypassing intended encryption protections and gaining elevated access.
CVE-2025-7472: Installer Privilege Escalation
Older versions of the Sophos Windows installer run under the SYSTEM context but do not correctly restrict file permissions. This enables attackers to replace or manipulate files, resulting in code execution as SYSTEM.
Which Versions Are Affected?
Here is a breakdown of the impacted and fixed versions:
| CVE | Affected Component | Fixed Version | Impact | Severity |
|---|---|---|---|---|
| CVE-2024-13972 | Updater (Registry ACLs) | 2024.3.2, FTS 2024.3.2.23.2, LTS 2026.0.1.1.2 | Local Privilege Escalation | High |
| CVE-2025-7433 | Device Encryption Module | 2026.1, FTS/LTS builds | Arbitrary Code Execution | High |
| CVE-2025-7472 | Windows Installer | Version 1.22 (March 6, 2025) | Local Privilege Escalation | High |
What Is the Risk for Enterprises?
Enterprises using vulnerable versions of Intercept X for Windows are exposed to:
-
Unauthorized privilege escalation
-
System-level compromise
-
Failure of endpoint encryption guarantees
Even environments with hardened security policies may be affected due to default SYSTEM-level installer execution or auto-updating mechanisms that have not yet applied the latest fixes.
Are There Any Workarounds?
No, there are currently no workarounds available for these vulnerabilities. The only mitigation is to immediately install the patched versions provided by Sophos.
How to Apply the Fixes
Organizations should do the following:
-
Upgrade Intercept X to version 2024.3.2 or newer
-
Ensure Device Encryption is at version 2026.1
-
Download installer version 1.22 or later
-
Check and enable auto-update policies for Recommended packages
-
Manually update any custom FTS or LTS channels
Where to Download the Latest Updates?
The latest patched versions can be downloaded from:
-
Sophos Central (official portal)
-
Use “Recommended” or latest “Maintenance” channels for automated updates
Why Is Timely Patching Critical?
Delaying updates increases exposure to local privilege escalation (LPE) attacks that can:
-
Bypass endpoint security controls
-
Lead to full system takeover
-
Open the door for ransomware, backdoors, or further lateral movement inside corporate networks
How to Confirm You're Safe?
To verify protection:
-
Ensure all components are running the latest supported versions
-
Disable access to old installer packages
-
Audit registry permissions and installation logs
Conclusion
Sophos Intercept X for Windows vulnerabilities present a serious threat to endpoint security through local exploitation paths. Organizations relying on outdated software are highly vulnerable to privilege escalation and code execution attacks.
Security teams must act immediately to apply all relevant patches, verify update compliance, and review installer usage to ensure enterprise-wide protection.
To take this further with guided labs and an instructor, see our SOC analyst training in Pune.
Related reading
- How Do CVE-2025-22230 and CVE-2025-22247 in VMware Tools Give SYSTEM Access? Full Exploit Breakdown and Patch Guide
- What are CVE-2025-27210 and CVE-2025-27209 vulnerabilities in Node.js, and how can Windows applications protect against these high-severity flaws?
- China-Linked Threat Group UNC5221 Exploits Ivanti Vulnerability CVE-2025-22457 for Remote Code Execution and Malware Deployment in Enterprise Networks
Reference
For the authoritative details, see National Vulnerability Database.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0