Intego · Intego Antivirus For Windows · CVE-2026-107707
**Name of the Vulnerable Software and Affected Versions**
Intego Antivirus for Windows versions prior to 3.0.0.1
**Description**
A link following issue exists in the optimization module. This allows local unprivileged users to delete arbitrary folders with SYSTEM privileges. An attacker can replace the directory of a scanned duplicate file with a junction to `C:Config.msi` and leverage the Windows Installer rollback mechanism to execute code as SYSTEM.
**Recommendations**
Update Intego Antivirus for Windows to a version newer than 3.0.0.1.