Zero‑Day Local Privilege Escalation in Glarysoft Glary Utilities Enables SYSTEM Code Execution
What Happened — A newly disclosed zero‑day (ZDI‑26‑402) in Glarysoft’s Glary Utilities lets a local attacker create a malicious junction that the Disk Clean service follows, deleting arbitrary files and executing code with SYSTEM privileges. The flaw requires only low‑privileged code execution on the host to be exploitable.
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access Control (CC6.1) mandates least‑privilege enforcement and continuous monitoring of privileged actions; this vulnerability shows the risk when third‑party utilities bypass those controls.
- Mapping this flaw to your control inventory and capturing remediation evidence satisfies audit requirements for “change management” and “risk mitigation” under the Trust Services Criteria.
- Continuous evidence collection (e.g., endpoint logs, patch status) provides defensible proof that the control gap has been closed.
Who Is Affected — Organizations that deploy Glary Utilities on Windows workstations, notably in technology SaaS, financial services, and professional services environments.
Recommended Actions
- Deploy any vendor‑issued patch immediately; if none is available, disable or restrict the Disk Clean feature to admin‑only accounts.
- Add Glary Utilities to your endpoint‑software inventory and map it to SOC 2 CC6.1 controls; capture patch‑status and usage logs as audit evidence.
- Implement continuous monitoring for suspicious file‑deletion activity and privilege‑escalation alerts on affected hosts. Source: Zero Day Initiative advisory
Technical Notes
- CVSS 7.3 (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
- Exploits the Disk Clean functionality by creating a junction that the service follows, leading to arbitrary file deletion and SYSTEM‑level code execution. Source: ZDI advisory