Local Privilege Escalation in Intercept X for Windows by Sophos
CVE-2025-7472

7.5HIGH

Key Information:

Vendor

Sophos

Vendor
CVE Published:
17 July 2025

Badges

👾 Exploit Exists📰 News Worthy

What is CVE-2025-7472?

A local privilege escalation vulnerability exists in the Intercept X for Windows installer, allowing local users to gain system-level privileges when executed with SYSTEM-level access. This flaw poses significant risks if exploited, leading to unauthorized actions on the affected systems. Users are advised to update to version 1.22 or later to mitigate potential security threats.

Affected Version(s)

Sophos Intercept X for Windows Installer Windows 0 < 1.22

News Articles

Sophos Intercept X for Windows Flaws Enable Arbitrary Code Execution

Sophos has disclosed three vulnerabilities in its Intercept X for Windows endpoint security solution that could allow attackers to execute arbitrary code.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by GBHackers News

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sandro Poppi https://medium.com/@spoppi
.
CVE-2025-7472 : Local Privilege Escalation in Intercept X for Windows by Sophos