Back to Labs
Security Advisory

CVE-2024-8885

About

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.

Weakness (CWE):CWE-502CWE-1104

Rainforest analyst review

This is a local privilege-escalation flaw in Sophos Intercept X with Central Device Encryption, where an insecure-deserialization weakness allows writing arbitrary files. The pointed irony is that the vulnerable software is a security and encryption product running with high privilege; abusing it lets a low-privileged local user write files they shouldn't, a classic stepping stone to full control of the host.

The vector is local and needs an existing low-privilege foothold, so this isn't an intrusion starter — it's what an attacker reaches for after landing on a machine to climb toward SYSTEM. Arbitrary file write from a low-privilege account against a highly privileged security agent is a strong escalation primitive, and the scope change signals the impact reaches beyond the component's own boundary.

We treat this as post-compromise escalation on endpoints and prioritize it through the lens of what runs everywhere. Endpoint security agents are deployed fleet-wide, so a version behind on this fix is a uniform escalation path across many machines. The control is straightforward — get the Sophos agent updated across the estate — but we rank it seriously because it turns any minor local foothold into a route to full host takeover.

References

Related CVEs

Frequently asked questions

What is CVE-2024-8885?

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2024.2.0 and older allows writing of arbitrary files.

How severe is CVE-2024-8885?

CVE-2024-8885 carries a CVSS 3.1 base score of 8.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 84 out of 100, in the high band.

How is CVE-2024-8885 exploited?

According to the CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H): attack vector Local, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.

How do I fix CVE-2024-8885?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email