Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged users to delete arbitrary folders as SYSTEM. Attackers can replace a scanned duplicate file's directory with a junction to C:\Config.msi and abuse Windows Installer rollback to execute code as SYSTEM.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 08 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its optimization module that allows local unprivileged users to delete arbitrary folders as SYSTEM. Attackers can replace a scanned duplicate file's directory with a junction to C:\Config.msi and abuse Windows Installer rollback to execute code as SYSTEM. | |
| Title | Intego Antivirus through 3.0.0.1 Local Privilege Escalation via Optimization Module Junction | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-08T19:51:14.469Z
Reserved: 2026-10-08T16:52:24.550Z
Link: CVE-2026-107707
No data.
Status : Received
Published: 2026-10-08T20:17:35.690
Modified: 2026-10-08T20:17:35.690
Link: CVE-2026-107707
No data.
OpenCVE Enrichment
No data.
Weaknesses