CVE-2002-2068
Status: ModifiedHigh (7.5)—
Eraser 5.3 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.16%
- Percentile among all scored CVEs: 82
- Score date: 10/3/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-459
References
- http://www.ciac.org/ciac/bulletins/m-034.shtml
- http://www.iss.net/security_center/static/7953.php
- http://www.securityfocus.com/archive/1/251565
- http://www.securityfocus.com/bid/3912
- http://www.seifried.org/security/advisories/kssa-003.html
- http://www.ciac.org/ciac/bulletins/m-034.shtml
- http://www.iss.net/security_center/static/7953.php
- http://www.securityfocus.com/archive/1/251565
- http://www.securityfocus.com/bid/3912
- http://www.seifried.org/security/advisories/kssa-003.html
Raw JSON (NVD)
Show
{
"id": "CVE-2002-2068",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2002-12-31T05:00:00.000",
"references": [
{
"url": "http://www.ciac.org/ciac/bulletins/m-034.shtml",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.iss.net/security_center/static/7953.php",
"tags": [
"Broken Link"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/251565",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/3912",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.seifried.org/security/advisories/kssa-003.html",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ciac.org/ciac/bulletins/m-034.shtml",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.iss.net/security_center/static/7953.php",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/251565",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/3912",
"tags": [
"Broken Link",
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.seifried.org/security/advisories/kssa-003.html",
"tags": [
"Broken Link",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-459"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Eraser 5.3 does not clear Windows alternate data streams that are attached to files on NTFS file systems, which allows attackers to recover sensitive information that was supposed to be deleted."
}
],
"lastModified": "2026-06-16T22:00:35.653",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:tolvanen:eraser:5.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58FA752B-F21C-4A61-B688-812A8FF4E98C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}