CyberRota Analysis
AI-GeneratedThe Uninstaller component in CCleaner versions prior to 7.10.1464 on Windows is vulnerable to a symlink/junction attack, enabling local low-privileged users to escalate their privileges to SYSTEM during the uninstallation process. This could allow attackers to manipulate or delete sensitive data with elevated permissions. Organizations using affected versions of CCleaner should prioritize patching this vulnerability to mitigate potential exploitation risks.
Original NVD Description
Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escalate privileges to SYSTEM via a symlink/junction created during application uninstallation, which CCleaner follows when deleting the application's data folder with elevated integrity.