{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/intego-antivirus-for-windows--3.0.0.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:intego:antivirus:*:*:*:*:*:windows:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-107707"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Intego Antivirus for Windows (\u003c= 3.0.0.1)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","windows","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Intego"],"content_html":"\u003cp\u003eIntego Antivirus for Windows versions 3.0.0.1 and earlier contain a critical link-following vulnerability within their optimization module. This flaw allows a local, unprivileged attacker to perform arbitrary file or directory deletions by abusing how the application handles file operations during the optimization process. By manipulating the filesystem environment, an attacker can trick the service into following a junction point to a sensitive location, such as C:\\Config.msi. Through subsequent interaction with the Windows Installer rollback mechanism, the attacker can influence the system state to execute arbitrary code with SYSTEM-level privileges. This vulnerability represents a significant security risk for Windows environments where multiple users share local access, as it enables the escalation of local user accounts to full system administrative control.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies the optimization module in Intego Antivirus performing file operations on user-controlled directories.\u003c/li\u003e\n\u003cli\u003eAttacker prepares a malicious directory structure to be scanned or processed by the antivirus.\u003c/li\u003e\n\u003cli\u003eAttacker deletes a target file or folder that the optimization module expects to encounter.\u003c/li\u003e\n\u003cli\u003eAttacker creates a filesystem directory junction at the target location pointing to C:\\Config.msi.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the optimization module, causing the service to follow the junction with elevated SYSTEM privileges.\u003c/li\u003e\n\u003cli\u003eAttacker monitors for Windows Installer activity or triggers an installer rollback process.\u003c/li\u003e\n\u003cli\u003eAttacker leverages the hijacked installer context to execute arbitrary malicious binaries as SYSTEM.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits an unprivileged local attacker to gain full SYSTEM privileges on the affected Windows host. This facilitates complete system compromise, including credential theft, installation of persistent backdoors, and total control over the operating system environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the upgrade of all Intego Antivirus for Windows installations to a version beyond 3.0.0.1 immediately, as no patch or workaround is currently described that mitigates the flaw without updating.\u003c/p\u003e\n","date_modified":"2026-10-08T22:07:51Z","date_published":"2026-10-08T22:07:51Z","id":"https://feed.craftedsignal.io/briefs/2026-10-intego-privesc/","summary":"A link-following vulnerability in the optimization module of Intego Antivirus for Windows through 3.0.0.1 allows local attackers to achieve arbitrary file deletion and privilege escalation to SYSTEM.","title":"Local Privilege Escalation in Intego Antivirus for Windows","url":"https://feed.craftedsignal.io/briefs/2026-10-intego-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Intego Antivirus for Windows (\u003c= 3.0.0.1)","version":"https://jsonfeed.org/version/1.1"}