Description
Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Glarysoft Glary Utilities. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the Disk Clean functionality. By creating a junction, an attacker can abuse the service to delete arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27004.
Published: 2026-07-13
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is exposed in the Disk Clean component of Glary Utilities. An attacker who has already obtained local code execution can craft a junction and trigger the. This path traversal flaw (CWE‑59) allows the attacker to gain SYSTEM privileges and execute code in the system context.

Affected Systems

All installations of Glarysoft Glary Utilities that include the Disk Clean feature and have not applied the vendor‑issued fix are vulnerable. The specific version range is not disclosed, so any unpatched copy remains at risk.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity local privilege escalation, while the EPSS score of < 1% signals a very low likelihood of exploitation in the wild. The flaw requires an initial local foothold; with that, an attacker can create the junction, invoke Disk Clean, and elevate privileges to system. The vulnerability is not listed in CISA KEV, but enterprise defenses such as disabling Disk Clean or restricting junction creation mitigate the risk.

Generated by OpenCVE AI on July 31, 2026 at 11:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch that removes the Disk Clean link‑following flaw, or if no patch is available, upgrade to the latest version of Glary Utilities.
  • Disable the Disk Clean feature in Glary Utilities to prevent exploitation of the flaw.
  • Restrict local user rights so that users cannot create junction points and cannot execute Disk Clean operations.

Generated by OpenCVE AI on July 31, 2026 at 11:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
First Time appeared Glarysoft
Glarysoft glary Utilities
Vendors & Products Glarysoft
Glarysoft glary Utilities

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Glarysoft Glary Utilities. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Disk Clean functionality. By creating a junction, an attacker can abuse the service to delete arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27004.
Title Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability
Weaknesses CWE-59
References
Metrics cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Glarysoft Glary Utilities
cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-07-14T13:00:33.375Z

Reserved: 2026-07-13T21:29:44.054Z

Link: CVE-2026-15684

cve-icon Vulnrichment

Updated: 2026-07-14T13:00:23.829Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:15:05Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')