CVE-2025-3025

7.3

Gen Digital · CCleaner

A local privilege escalation vulnerability in CCleaner version 6 allows authenticated users to gain SYSTEM privileges via insecure file delete operations.

Executive summary

A high-severity local privilege escalation vulnerability in Gen Digital CCleaner version 6 could allow a local user to gain full SYSTEM privileges on the affected Windows system.

Vulnerability

This vulnerability, categorized as CWE-552, involves insecure file delete operations within the cleaning feature of the software. A local, authenticated user can exploit these operations to elevate their standard user permissions to full SYSTEM-level access.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational security, as it allows a local attacker to bypass standard operating system protections. By gaining SYSTEM privileges, an attacker can install malicious software, access sensitive data, or modify system configurations, leading to a total compromise of the affected host. Given the CVSS score of 7.3, this flaw represents a significant risk that must be addressed to prevent unauthorized administrative control.

Remediation

Immediate Action: Update the CCleaner application to version 6.36.11508 or newer immediately to resolve the insecure file handling mechanism.

Proactive Monitoring: Review system logs for signs of unauthorized file manipulation or unexpected process execution occurring under the SYSTEM account.

Compensating Controls: Restrict local user access to the extent possible and ensure that non-administrative accounts have limited permissions on the filesystem to minimize the window for local exploitation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk of privilege escalation to SYSTEM level is critical for any environment utilizing CCleaner. Administrators should prioritize the deployment of version 6.36.11508 across all managed endpoints to remediate the vulnerability. Failure to patch may allow attackers who have gained a foothold on a system to escalate their permissions and achieve complete control over the affected workstation.

More Gen Digital CVEs

Sources

Originally found and disclosed by Dong-uk Kim (@justlikebono), with Trend Micro, the Zero Day Initiative (ZDI) ZDI-CAN-26474 (other), per the CVE Program record.