Home
HIGH: 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
Any version before 2025.1
affected
Description
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and older allows arbitrary code execution.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
Any version before 2025.1
Credits
Sina Kheirkhah (@SinSinology) of watchTowr (https://watchtowr.com)
References
www.sophos.com/...rity-advisories/sophos-sa-20250717-cix-lpe