HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Zero-Day Local Privilege Escalation in Glarysoft Glary Utilities Enables SYSTEM Code Execution

A newly disclosed 0‑day (ZDI‑26‑402) in Glarysoft’s Glary Utilities lets a local attacker create a junction to delete arbitrary files and execute code as SYSTEM. The flaw highlights the need for robust privilege‑management controls and continuous evidence of remediation in SOC 2 audits.

LiveThreat™ Intelligence · 📅 July 09, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Zero‑Day Local Privilege Escalation in Glarysoft Glary Utilities Enables SYSTEM Code Execution

What Happened — A newly disclosed zero‑day (ZDI‑26‑402) in Glarysoft’s Glary Utilities lets a local attacker create a malicious junction that the Disk Clean service follows, deleting arbitrary files and executing code with SYSTEM privileges. The flaw requires only low‑privileged code execution on the host to be exploitable.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Control (CC6.1) mandates least‑privilege enforcement and continuous monitoring of privileged actions; this vulnerability shows the risk when third‑party utilities bypass those controls.
  • Mapping this flaw to your control inventory and capturing remediation evidence satisfies audit requirements for “change management” and “risk mitigation” under the Trust Services Criteria.
  • Continuous evidence collection (e.g., endpoint logs, patch status) provides defensible proof that the control gap has been closed.

Who Is Affected — Organizations that deploy Glary Utilities on Windows workstations, notably in technology SaaS, financial services, and professional services environments.

Recommended Actions

  • Deploy any vendor‑issued patch immediately; if none is available, disable or restrict the Disk Clean feature to admin‑only accounts.
  • Add Glary Utilities to your endpoint‑software inventory and map it to SOC 2 CC6.1 controls; capture patch‑status and usage logs as audit evidence.
  • Implement continuous monitoring for suspicious file‑deletion activity and privilege‑escalation alerts on affected hosts. Source: Zero Day Initiative advisory

Technical Notes

  • CVSS 7.3 (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
  • Exploits the Disk Clean functionality by creating a junction that the service follows, leading to arbitrary file deletion and SYSTEM‑level code execution. Source: ZDI advisory
📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-402/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →