PT-2026-68174 · Piriform · Ccleaner
CVE-2026-12410
·
Published
2026-08-05
·
Updated
2026-08-13
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
CCleaner versions prior to 7.10.1464
Description
A link following issue exists in the Uninstaller component on Windows. A local, low-privileged attacker can escalate privileges to SYSTEM by creating a symlink or junction during the application uninstallation process. The software follows these links when deleting the application data folder with elevated integrity.
Recommendations
Update to version 7.10.1464 or later.
Fix
LPE
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ccleaner