Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsIn July 2016, security researchers Matt Nelson and Matt Graeber described how a Windows 10 scheduled task called SilentCleanup could be used in a specific tested scenario to reach a high-integrity process through a temporary DLL-loading race. Their report was about elevating code already running in a user context—not about Disk Cleanup freeing space, and not a claim that every Windows 10 computer or account was vulnerable.
What the 2016 report described
The task involved was MicrosoftWindowsDiskCleanupSilentCleanup. Nelson and Graeber reported that on the stock Windows 10 installations they examined, the task could be launched by an unprivileged user and was configured to run with highest privileges. It launched Disk Cleanup, cleanmgr.exe.
In their account, Disk Cleanup created a GUID-named folder in the user’s temporary directory, copied dismhost.exe and related DLLs into it, then started dismhost.exe at high integrity. Since a medium-integrity process could write to its own temporary directory, the researchers described a timing opportunity to replace LogProvider.dll before it was loaded. This is why the reported mechanism was a DLL-loading race—not simply running Disk Cleanup or deleting files. Their write-up said the temporary folder was removed when the task finished and that the technique worked with UAC set to “Always Notify.” Those details are the authors’ reported findings, not an independent test.
It was not a standard-user method in their tests
The authors explicitly said the route did not work for a standard user account in their testing. For a standard user, they reported, the task ran at medium integrity and cleanmgr.exe did not extract the files into %TEMP% as required for the described race. The account and integrity context therefore matter; “unprivileged user” should not be read as “any account on any Windows 10 PC.”
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
What “bypass UAC” means here
User Account Control (UAC) is the Windows mechanism that can prompt for approval or credentials when an operation needs elevation. In this report, the researchers described starting with code already running in the user’s context and attempting to reach a higher-integrity process. It was not an initial-compromise technique: an attacker would first need a way to run code in that context.
Nelson and Graeber said they reported the technique to Microsoft’s Security Response Center on July 20, 2016, and that Microsoft responded that UAC “isn’t a security boundary.” That phrasing is the researchers’ account of the response. Microsoft’s current Windows security servicing criteria classify UAC as a defense-in-depth feature. Microsoft says a bypass of such a feature, by itself, does not directly compromise a device because an attacker must also affect a security boundary or use another route, such as social engineering, to achieve initial compromise. The criteria say there is no default servicing plan for these defense-in-depth bypasses, although future versions may address them. That servicing classification does not mean UAC has no protective value.
Rank #2
- 15.6" diagonal, HD (1366 x 768), micro-edge, BrightView, 220 nits, 45% NTSC.
Does the 2016 technique work on Windows 10 today?
The sources available do not establish whether this exact DLL-race route works on particular current or historical Windows 10 builds. The original report describes the researchers’ tested installations; it is not a build-by-build compatibility record. Google Project Zero’s February 2026 discussion mentions SilentCleanup among tasks used in earlier UAC bypasses, but addresses a separate Administrator Protection issue in the version its researcher tested and says the issues in that investigation were fixed. It does not demonstrate that the 2016 technique works on all current systems.
There is also a lifecycle issue for anyone still using Windows 10. Microsoft’s support notice says Windows 10 support ended on October 14, 2025; after that date, Microsoft no longer provides free Windows Update software updates, technical assistance, or security fixes for Windows 10. Check whether your particular edition or servicing arrangement remains supported rather than inferring present-day protection from the 2016 report.
Recommended Free Tools
Rank #3
- 10th Generation Intel Core i5-1035G1 processor
- 12GB system memory for full-power multitasking
- 256GB Solid State Drive
- 15.6" Micro-edge touchscreen display
What defenders can monitor
The researchers’ 2016 defensive suggestions included disabling the SilentCleanup task or removing its “run with highest privileges” requirement, monitoring the WMI event their proof of concept used, applying application or DLL allowlisting, and watching for unusual module loads—citing Sysmon Event ID 7 as one example. These were their suggested mitigations, not a universal current hardening baseline. Administrators should assess operational effects before changing a Windows maintenance task.
SigmaHQ maintains a process-creation detection rule for a Disk Cleanup UAC bypass. It looks for a pattern including cleanmgr.exe /autoclean /d C:, Task Scheduler’s service host as the parent, and high or system integrity. The rule metadata lists Christian Burkard as author, August 30, 2021 as its original date, December 1, 2024 as its modification date, and high severity; false positives are listed as unknown. Treat a match as an investigative lead, not proof of compromise, and test and tune the rule against local telemetry.
Rank #4
- Latitude 7480 Laptop 14"
- Intel Core i7 6th Gen i7-6600U -Core Processor 2.6GHz (3.4GHz With Turbo Boost)
- 256 GB SSD Hard Drive & 16GB Memory
- 1920x1080 FHD resolution Non-Touch with Webcam and an integrated graphics chip
- Wireless Wifi & Bluetooth
Why the report still matters
The report is useful as a case study in how a scheduled task’s privilege configuration and writable temporary files can interact. The researchers said their approach did not require process injection or a privileged file copy; that is their assessment of the technique, not a comparison established by independent testing. Its practical meaning depends on the account context, Windows configuration, and the exact build—details that prevent the 2016 write-up from serving as evidence of a current, universal Windows 10 vulnerability.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

