PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12410 Gen Digital CVE debrief

A local, low-privileged attacker can exploit a link following vulnerability in CCleaner's Uninstaller component prior to version 7.10.1464 on Windows to escalate privileges to SYSTEM. This occurs when a symlink/junction is created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity.

Vendor
Gen Digital
Product
CCleaner
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-09-08
Advisory published
2026-08-05
Advisory updated
2026-09-08

Who should care

Defenders responsible for managing and securing CCleaner installations, particularly in environments where local, low-privileged access is common, should assess exposure and prioritize remediation.

Why it matters

CVE-2026-12410 is a link following vulnerability in CCleaner's Uninstaller component that allows local privilege escalation to SYSTEM. Defenders should prioritize verifying and upgrading to the latest version of CCleaner, assessing exposure in their environment, and implementing compensating controls to limit potential damage. The vulnerability requires verification from official sources, and additional information on affected versions, exploitation, and remediation may be necessary for comprehensive risk assessment.

  • Verification of CCleaner version and exposure in the environment is necessary to determine potential risk.
  • Implementation of compensating controls, such as monitoring for suspicious activity related to CCleaner uninstallation, may be necessary to limit potential damage.
  • Remediation priority is high due to the potential for local privilege escalation to SYSTEM.
  • Additional information on affected versions and exploitation may be necessary for comprehensive risk assessment.

Technical summary

The vulnerability exists in the Uninstaller component of CCleaner prior to version 7.10.1464 on Windows. A local, low-privileged attacker can create a symlink/junction during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity, allowing for privilege escalation to SYSTEM. This vulnerability requires verification from official sources, and additional information on affected versions, exploitation, and remediation may be necessary for comprehensive risk assessment. Defenders should prioritize verifying and upgrading to the latest version of CCleaner, assessing exposure in their environment, and implementing compensating controls to limit potential

Defensive priority

Defenders should prioritize verifying and upgrading to the latest version of CCleaner, assessing exposure in their environment, and implementing compensating controls to limit potential damage.

Recommended defensive actions

  • Verify and upgrade to the latest version of CCleaner
  • Assess exposure in the environment
  • Implement compensating controls to limit potential damage
  • Monitor for suspicious activity related to CCleaner uninstallation
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details on the vulnerability in CCleaner's Uninstaller component prior to version 7.10.1464 on Windows. A local, low-privileged attacker can create a symlink/junction during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity. Additional information on affected versions, exploitation, and remediation may be necessary for comprehensive risk assessment. Defenders should verify and upgrade to the latest version of CCleaner, assess the

Sources and references

Verified primary and authoritative sources

  • CVE-2026-12410 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-12410

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-12410 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12410

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.