Backdoor in CCleaner - #VU11316

 

Backdoor in CCleaner - #VU11316

Published: March 28, 2018 / Updated: November 22, 2018


Vulnerability identifier: #VU11316
CSH Severity: Critical
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: The vulnerability is being exploited in the wild

Vulnerability details

CCleaner version 5.33.6162 and CCleaner Cloud version 1.07.3191 were shipped with a backdoor code from official vendor’s website. The incident was detected on September 12.

The malicious version was released on August 15. Users, who downloaded CCleaner between August 15 and September 12, are affected.


Affected software

CCleaner

Remediation

Update to version 5.33.6163.


External References

Related Security Bulletins