← Back to searchJSON

CVE-2026-12410

7.8 HIGH

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
This vulnerability allows a low-privileged user to escalate privileges by creating symlinks during CCleaner uninstallation, potentially gaining SYSTEM access. It matters because it can lead to unauthorized system control.
Exploitability
Exploitation requires local access and knowledge of the specific symlink technique used in the uninstall process; not trivial but feasible for advanced attackers.
Blast radius
If exploited, the impact could be severe, allowing full control over the affected system with SYSTEM privileges.
Prioritized remediation
Update to CCleaner version 7.10.1464 or later to mitigate this vulnerability.
privilege-escalationlocal-attackuninstaller

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-59

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.