DLL Hijacking Vulnerability in BleachBit for Windows
CVE-2025-32780

7.3HIGH

Key Information:

Vendor

Bleachbit

Status
Vendor
CVE Published:
15 April 2025

What is CVE-2025-32780?

BleachBit for Windows, a utility for cleaning files to free up disk space and maintain user privacy, is susceptible to a vulnerability that enables DLL Hijacking. This flaw allows an attacker to place a malicious DLL file named 'uuid.dll' in the user's local application data directory (C:\Users<username>\AppData\Local\Microsoft\WindowsApps). When BleachBit is executed, the malicious code can be run, potentially compromising the system. Users are strongly advised to update to version 4.9.0 or later to mitigate this threat and safeguard their systems.

Affected Version(s)

bleachbit < 4.9.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.