CVE-2017-20201 describes a supply chain compromise affecting CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds). Malicious code was embedded, diverting execution to a custom loader that deployed an in-memory payload for data collection and exfiltration to hard-coded or DGA C2 servers. This critical vulnerability (CVSS 9.3) has a network attack vector and low attack complexity, allowing unauthenticated attackers to achieve high confidentiality and integrity impacts through remote data collection and stealthy in-memory execution. While not listed on the KEV catalog, the vulnerability was actively exploited in the wild as a supply chain attack. There are no public Metasploit, Nuclei, or ExploitDB modules, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Piriform | CCleaner Cloud | 1.07.3191CNA affecteddefault unaffected | |
| Piriform | CCleaner | 5.33.6162CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.