We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-32780

BleachBit for Windows Has DLL Untrusted Path Vulnerability



Description

BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerable to a DLL Hijacking vulnerability. By placing a malicious DLL with the name uuid.dll in the folder C:\Users\<username>\AppData\Local\Microsoft\WindowsApps\, an attacker can execute arbitrary code every time BleachBit is run. This issue has been patched in version 4.9.0.

Reserved 2025-04-10 | Published 2025-04-15 | Updated 2025-04-15 | Assigner GitHub_M


HIGH: 7.3CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-427: Uncontrolled Search Path Element

Product status

< 4.9.0
affected

References

github.com/...achbit/security/advisories/GHSA-ghph-v4x4-vr3c

github.com/...ommit/dafeba57dcb14c7ec4a97224ff1408f6b0c2a7f8

cve.org (CVE-2025-32780)

nvd.nist.gov (CVE-2025-32780)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-32780

Support options

Helpdesk Chat, Email, Knowledgebase