Local Privilege Escalation in Intercept X for Windows by Sophos
CVE-2025-7472

7.5HIGH

Key Information:

Vendor

Sophos

Vendor
CVE Published:
17 July 2025

What is CVE-2025-7472?

A local privilege escalation vulnerability exists in the Intercept X for Windows installer, allowing local users to gain system-level privileges when executed with SYSTEM-level access. This flaw poses significant risks if exploited, leading to unauthorized actions on the affected systems. Users are advised to update to version 1.22 or later to mitigate potential security threats.

Affected Version(s)

Sophos Intercept X for Windows Installer Windows 0 < 1.22

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sandro Poppi https://medium.com/@spoppi
.
CVE-2025-7472 : Local Privilege Escalation in Intercept X for Windows by Sophos