CVE-2025-7433: High severity Sophos Intercept X for Windows with Central Device Encryption vulnerability
Published Jul 17, 2025
·Updated
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and older allows arbitrary code execution.
Affected Software
1 affected component
Sophos Intercept X for Windows with Central Device Encryption<2025.1
Event History
Jul 17, 2025
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Mar 17, 57529
Event
via FIRST·09:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2025-7433?
CVE-2025-7433 is classified as a high severity local privilege escalation vulnerability.
2
How do I fix CVE-2025-7433?
To fix CVE-2025-7433, upgrade Sophos Intercept X for Windows with Central Device Encryption to version 2025.2 or later.
3
What are the implications of CVE-2025-7433?
CVE-2025-7433 allows attackers to execute arbitrary code with elevated privileges on affected systems.
4
Which versions of Sophos Intercept X are affected by CVE-2025-7433?
CVE-2025-7433 affects Sophos Intercept X for Windows with Central Device Encryption versions up to 2025.1.
5
Is there a workaround for CVE-2025-7433?
There are currently no known workarounds for CVE-2025-7433; the recommendation is to update to the latest version.