CVE-2026-12410: CCleaner local privilege escalation via link following on uninstall
Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
CCleanerto a version that resolves this vulnerability.Fixed in 7.10.1464
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12410?
CVE-2026-12410 has a severity rating of high with a score of 7.8.
How do I fix CVE-2026-12410?
To fix CVE-2026-12410, upgrade to CCleaner version 7.10.1464 or later.
What type of attack does CVE-2026-12410 involve?
CVE-2026-12410 involves a local privilege escalation attack due to link following during uninstallation.
Who is affected by CVE-2026-12410?
CVE-2026-12410 affects users of CCleaner prior to version 7.10.1464 on Windows.
What impact does CVE-2026-12410 have on systems?
CVE-2026-12410 allows a low-privileged attacker to escalate privileges to SYSTEM, potentially compromising the system's security.