Sophos Intercept X
cpe:2.3:a:sophos:intercept_x_endpoint:*:*:*:*:*:*:*
- < 2024.3.2
A vulnerability in the Intercept X for Windows updater prior to version 2024.3.2 allows local users to gain SYSTEM-level privileges during product upgrades, due to improper registry permissions.
Exploitation of this vulnerability could result in unauthorized local users gaining elevated privileges, allowing them to execute actions or commands with SYSTEM-level rights.
Users should upgrade to Sophos Intercept X for Windows version 2024.3.2 or later. For those using Fixed Term Support (FTS) or Long Term Support (LTS) packages, the latest versions can be downloaded from Sophos Central.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.