PatchSiren cyber security CVE debrief
CVE-2026-12410 Gen Digital CVE debrief
A local, low-privileged attacker can exploit a link following vulnerability in CCleaner's Uninstaller component prior to version 7.10.1464 on Windows to escalate privileges to SYSTEM. This occurs when a symlink/junction is created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity.
- Vendor
- Gen Digital
- Product
- CCleaner
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-05
- Original CVE updated
- 2026-09-08
- Advisory published
- 2026-08-05
- Advisory updated
- 2026-09-08
Who should care
Defenders responsible for managing and securing CCleaner installations, particularly in environments where local, low-privileged access is common, should assess exposure and prioritize remediation.
Why it matters
CVE-2026-12410 is a link following vulnerability in CCleaner's Uninstaller component that allows local privilege escalation to SYSTEM. Defenders should prioritize verifying and upgrading to the latest version of CCleaner, assessing exposure in their environment, and implementing compensating controls to limit potential damage. The vulnerability requires verification from official sources, and additional information on affected versions, exploitation, and remediation may be necessary for comprehensive risk assessment.
- Verification of CCleaner version and exposure in the environment is necessary to determine potential risk.
- Implementation of compensating controls, such as monitoring for suspicious activity related to CCleaner uninstallation, may be necessary to limit potential damage.
- Remediation priority is high due to the potential for local privilege escalation to SYSTEM.
- Additional information on affected versions and exploitation may be necessary for comprehensive risk assessment.
Technical summary
The vulnerability exists in the Uninstaller component of CCleaner prior to version 7.10.1464 on Windows. A local, low-privileged attacker can create a symlink/junction during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity, allowing for privilege escalation to SYSTEM. This vulnerability requires verification from official sources, and additional information on affected versions, exploitation, and remediation may be necessary for comprehensive risk assessment. Defenders should prioritize verifying and upgrading to the latest version of CCleaner, assessing exposure in their environment, and implementing compensating controls to limit potential
Defensive priority
Defenders should prioritize verifying and upgrading to the latest version of CCleaner, assessing exposure in their environment, and implementing compensating controls to limit potential damage.
Recommended defensive actions
- Verify and upgrade to the latest version of CCleaner
- Assess exposure in the environment
- Implement compensating controls to limit potential damage
- Monitor for suspicious activity related to CCleaner uninstallation
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details on the vulnerability in CCleaner's Uninstaller component prior to version 7.10.1464 on Windows. A local, low-privileged attacker can create a symlink/junction during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity. Additional information on affected versions, exploitation, and remediation may be necessary for comprehensive risk assessment. Defenders should verify and upgrade to the latest version of CCleaner, assess the
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12410 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12410
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12410 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12410
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.gendigital.com/us/en/contact-us/security-advisories/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.