First published: Tue Apr 15 2025(Updated: )
BleachBit cleans files to free disk space and to maintain privacy. BleachBit for Windows up to version 4.6.2 is vulnerable to a DLL Hijacking vulnerability. By placing a malicious DLL with the name uuid.dll in the folder C:\Users\<username>\AppData\Local\Microsoft\WindowsApps\, an attacker can execute arbitrary code every time BleachBit is run. This issue has been patched in version 4.9.0.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
BleachBit | <4.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-32780 is classified as a medium severity DLL Hijacking vulnerability.
To mitigate CVE-2025-32780, update BleachBit to version 4.6.3 or later, which resolves the vulnerability.
BleachBit versions up to and including 4.6.2 are affected by CVE-2025-32780.
CVE-2025-32780 enables an attacker to execute arbitrary code by placing a malicious DLL in a specific folder.
The vendor of the affected software is BleachBit.