CVE-2026-107707: Intego Antivirus through 3.0.0.1 Local Privilege Escalation via Optimization Module Junction
Published Oct 8, 2026
·Updated
Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged users to delete arbitrary folders as SYSTEM. Attackers can replace a scanned duplicate file's directory with a junction to C:\Config.msi and abuse Windows Installer rollback to execute code as SYSTEM.
Affected Software
1 affected component
Intego Antivirus for Windows<=3.0.0.1
Event History
Oct 8, 2026
CVE Published
via MITRE·07:51 PM
Data Sourced
via MITRE·07:51 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
A local unprivileged user can exploit it. The reported impact is deletion of arbitrary folders as SYSTEM and potential execution of code as SYSTEM.
2
What conditions are required for exploitation?
The attacker needs to target the optimization module's handling of a scanned duplicate file, replace that file's directory with a junction to C:\Config.msi, and abuse Windows Installer rollback.