ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-565: Gen Digital CCleaner Link Following Local Privilege Escalation Vulnerability

mediumVulnerabilityimportance 20CVE-2026-12410
AI summary · glm-5.3-flash

A link-following flaw (CVE-2026-12410, CVSS 7.8) in Gen Digital CCleaner allows local privilege escalation after low-privileged code execution.

ZDI advisory ZDI-26-565 details a link following vulnerability in Gen Digital CCleaner that permits local privilege escalation. An attacker must first be able to run low-privileged code on the affected installation. ZDI rated the issue 7.8 on CVSS and assigned CVE-2026-12410.

  • Local privilege escalation in Gen Digital CCleaner via link following.
  • Requires prior low-privileged code execution on the system.
  • CVSS 7.8; tracked as CVE-2026-12410 under ZDI-26-565.

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-12410
Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileg

Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity.

NVD description · AI analysis pending
7.8<1%
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Gen Digital CCleaner. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-12410.

This source does not provide full text. Read it at zerodayinitiative.com.