CVE-2024-13972: High severity Sophos Intercept X for Windows vulnerability
Published Jul 17, 2025
·Updated
A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.3.2 can lead to a local user gaining SYSTEM level privileges during a product upgrade.
Affected Software
1 affected component
Sophos Intercept X for Windows<2024.3.2
Event History
Jul 17, 2025
CVE Published
via MITRE·07:02 PM
Data Sourced
via MITRE·07:02 PM
DescriptionSeverity
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-13972?
CVE-2024-13972 has a high severity due to its potential for local privilege escalation.
2
How do I fix CVE-2024-13972?
To fix CVE-2024-13972, update to Sophos Intercept X for Windows version 2024.3.2 or later.
3
Who is affected by CVE-2024-13972?
CVE-2024-13972 affects users of Sophos Intercept X for Windows versions prior to 2024.3.2.
4
What types of attacks can exploit CVE-2024-13972?
CVE-2024-13972 can be exploited by local users to gain system-level privileges during software upgrading.
5
Is there a workaround for CVE-2024-13972?
There is no official workaround for CVE-2024-13972; updating is recommended to mitigate the risk.