CVE-2015-3999

UnknownEPSS 0.52%

Last modified

CVE-2015-3999 is a vulnerability of currently unknown severity. Piriform CCleaner 3.26.0.1988 through 5.02.5101 writes the filenames to disk when overwriting files, which allows local users to obtain sensitive information by searching unallocated disk space.. EPSS estimates a 0.52% chance of exploitation in the next 30 days.

Description

Piriform CCleaner 3.26.0.1988 through 5.02.5101 writes the filenames to disk when overwriting files, which allows local users to obtain sensitive information by searching unallocated disk space.

Metrics

EPSS Probability
0.52%

40.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
PiriformCcleaner3.26.1888
PiriformCcleaner3.27.1900
PiriformCcleaner3.28.1913
PiriformCcleaner4.00.4064
PiriformCcleaner4.01.4093
PiriformCcleaner4.02.4115
PiriformCcleaner4.03.4151
PiriformCcleaner4.04.4197
PiriformCcleaner4.05.4250
PiriformCcleaner4.06.4324
PiriformCcleaner4.07.4369
PiriformCcleaner4.08.4428
PiriformCcleaner4.09.4471
PiriformCcleaner4.10.4570
PiriformCcleaner4.11.4619
PiriformCcleaner4.12.4657
PiriformCcleaner4.13.4693
PiriformCcleaner4.14.4707
PiriformCcleaner4.15.4725
PiriformCcleaner4.16.4763
PiriformCcleaner4.17.4808
PiriformCcleaner4.18.4844
PiriformCcleaner4.19.4867
PiriformCcleaner5.00.5050
PiriformCcleaner5.01.5075
PiriformCcleaner5.02.5101

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2015-3999?
Piriform CCleaner 3.26.0.1988 through 5.02.5101 writes the filenames to disk when overwriting files, which allows local users to obtain sensitive information by searching unallocated disk space.
How severe is CVE-2015-3999?
Severity scoring for CVE-2015-3999 is pending analysis. The EPSS model estimates a 0.52% probability of exploitation in the next 30 days.
How do I fix CVE-2015-3999?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2015-3999?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST