CVE-2017-20201 Details
Description
CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds) contained a malicious pre-entry-point loader that diverts execution from __scrt_common_main_seh into a custom loader. That loader decodes an embedded blob into shellcode, allocates executable heap memory, resolves Windows API functions at runtime, and transfers execution to an in-memory payload. The payload performs anti-analysis checks, gathers host telemetry, encodes the data with a two-stage obfuscation, and attempts HTTPS exfiltration to hard-coded C2 servers or month-based DGA domains. Potential impacts include remote data collection and exfiltration, stealthy in-memory execution and persistence, and potential lateral movement. CCleaner was developed by Piriform, which was acquired by Avast in July 2017; Avast later merged with NortonLifeLock to form the parent company now known as Gen Digital. According to vendor advisories, the compromised CCleaner build was released on August 15, 2017 and remediated on September 12, 2017 with v5.34; the compromised CCleaner Cloud build was released on August 24, 2017 and remediated on September 15, 2017 with v1.07.3214.
A supply chain attack was discovered in CCleaner version 5.33.6162 and CCleaner Cloud version 1.07.3191, both 32-bit builds. The attack involved a malicious pre-entry-point loader that redirected execution to a custom loader. This loader decoded an embedded blob into shellcode, which was then executed in memory. The payload performed anti-analysis checks, collected telemetry data from the host, and exfiltrated this data to command and control (C2) servers via HTTPS. The malware also had the capability to persist on the system and potentially move laterally within a network.
Users are advised to update to the latest version of CCleaner. Version 5.34 is available for download on the CCleaner website. For CCleaner Cloud users, version 1.07.3214 is the recommended update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 8, 2025CISA-ADP
Assessed Oct 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-506 | Embedded Malicious Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Piriform CCleaner | 5.33.6162 (semver) |
CPE
Remediation
| |
| Piriform CCleaner Cloud | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 14, 2025 | CVE Modified | CISA-ADP |
| Oct 8, 2025 | New CVE Received | [email protected] |
Volerion