CVE-2002-0788 describes a vulnerability in PGP 7.0.3 (Corporate Desktop, Freeware, and Personal Security) where using the "wipe deleted files" option on Windows Encrypted File System (EFS) creates unwipeable cleartext temporary files. This local vulnerability, rated Medium severity (CVSS 5.5), allows local users or attackers with physical access to recover sensitive information due to strong permissions preventing proper deletion. There is no evidence of active exploitation, nor are there publicly available exploit modules, though the vulnerability has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1CPE matchmatch criteria | cpe:2.3:a:pgp:corporate_desktop:7.1:*:*:*:*:*:*:* | ||
7.0.3CPE matchmatch criteria | cpe:2.3:a:pgp:freeware:7.0.3:*:*:*:*:*:*:* | ||
7.0.3CPE matchmatch criteria | cpe:2.3:a:pgp:personal_security:7.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.