Home
HIGH: 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
Any version before 2024.3.2
affected
Description
A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.3.2 can lead to a local user gaining SYSTEM level privileges during a product upgrade.
Problem types
CWE-276 Incorrect Default Permissions
Product status
Any version before 2024.3.2
Credits
Filip Dragovic of MDSec (https://www.mdsec.co.uk/)
References
www.sophos.com/...rity-advisories/sophos-sa-20250717-cix-lpe