CVE-2025-3025
BaseFortify
Publication date: 2025-09-15
Last updated on: 2025-09-15
Assigner: NortonLifeLock Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| avast | avast_antivirus | <24.2 |
| gendigital | ccleaner | 6.33.11465 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-552 | The product makes files or directories accessible to unauthorized actors, even though they should not be. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an elevation of privileges issue in the cleaning feature of Gen Digital CCleaner version 6.33.11465 on Windows. It allows a local user to gain SYSTEM privileges by exploiting insecure file delete operations.
How can this vulnerability impact me? :
An attacker with local access could exploit this vulnerability to gain SYSTEM-level privileges, which means they could execute code with the highest level of permissions on the affected system. This could lead to full control over the system, including installing software, accessing sensitive data, or disrupting system operations.
What immediate steps should I take to mitigate this vulnerability?
Update CCleaner to version 6.36.11508 or later to fix the elevation of privileges vulnerability caused by insecure file delete operations.