Impact
The vulnerability involves a link following flaw in the CCleaner uninstaller that occurs before version 7.10.1464 on Windows. When an uninstall is performed, CCleaner deletes the application’s data folder. If a local, low‑privilege user has created a symlink or junction pointing to a protected location during that process, CCleaner follows that path with elevated integrity levels and deletes the targeted contents. This grants the attacker the SYSTEM account, allowing full control over the affected machine. The weakness directly maps to CWE‑59, a classic path traversal / link following issue.
Affected Systems
Gen Digital’s CCleaner for Windows, versions earlier than 7.10.1464, are affected. All releases of 7.10.1464 and later contain the fix.
Risk and Exploitability
The CVSS score is 7.8, classifying the flaw as high severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalogue, implying no known public exploits at the time of analysis. The attack requires a local user on the target system who can execute CCleaner’s uninstaller, typically during a standard uninstall request. Because the exploit leverages a routine Windows administrative action (deleting files), it is considered feasible for a motivated attacker with local access.
OpenCVE Enrichment