CVE-2025-32780
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Apr 15, 2025
CWE ID 427
Summary
CVE-2025-32780 is a DLL hijacking vulnerability affecting BleachBit, a utility used to clean files and maintain privacy on Windows systems. The flaw, present in versions 4.6.2 and below, allows an attacker to execute arbitrary code by placing a malicious uuid.dll file in the specific folder C:\\Users\\<username>\\AppData\\Local\\Microsoft\\WindowsApps\\. With this manipulation, BleachBit will inadvertently load the malicious DLL instead of the intended one, thereby compromising the system. This issue has since been mitigated in BleachBit version 4.9.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- BleachBit
Affected Vendors
- Bleachbit