Sophos disclosed and remediated three high-severity local privilege escalation vulnerabilities in Sophos Endpoint and Workload Protection for Windows, Sophos Central Device Encryption, and the Windows installer, tracked as CVE-2024-13972, CVE-2025-7433, and CVE-2025-7472. The flaws could allow a local user to gain SYSTEM privileges, and CVE-2025-7433 could also enable arbitrary code execution. Sophos said customers using the default Recommended update policy generally received fixes automatically, while organizations on FTS, LTS, or using older installer packages must upgrade manually and, for installer-related exposure, download a fresh installer from Sophos Central.
Details published on CVE-2025-7433 describe a CWE-502 deserialization of untrusted data issue in the encryption service of Sophos Intercept X for Windows with Central Device Encryption, affecting versions prior to 2025.1 and allowing crafted serialized payloads to run code as SYSTEM during configuration, policy, or inter-process message handling. Sophos said fixes are available in FTS 2024.3.2 and later and LTS 2024.1.1.50 and later. The disclosure follows an earlier Device Encryption privilege-escalation bug, CVE-2024-8885, which allowed arbitrary file writing in version 2024.2.0 and older and was fixed in 2024.2.1.6; Sophos credited external researchers including Filip Dragovic of MDSec, Sina Kheirkhah of watchTowr, and Sandro Poppi via its bug bounty program.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Sophos disclosed and fixed three independent high-severity local privilege escalation vulnerabilities affecting Sophos Endpoint and Workload Protection for Windows, Sophos Central Device Encryption, and the Windows installer. The flaws were tracked as CVE-2024-13972, CVE-2025-7433, and CVE-2025-7472, and Sophos said default-policy customers generally receive updates automatically while some FTS, LTS, and older installer users must upgrade manually.
Sophos included remediation for the local privilege escalation vulnerability CVE-2024-8885 in Device Encryption version 2024.2.1.6. The fix addressed an arbitrary file write issue affecting Sophos Intercept X for Windows with Central Device Encryption version 2024.2.0 and older.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
sophos.com
Open sourcesophos.com
Open sourcezeropath.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.