vendor:
Notepad++
by:
anT!-Tr0J4n
8.8
CVSS
HIGH
Arbitrary Code Execution
119
CWE
Product Name: Notepad++
Affected Version From: 5.8.2002
Affected Version To: 5.8.2002
Patch Exists: NO
Related CWE:
CPE: a:notepad-plus-plus:notepad++:5.8.2
Platforms Tested: Windows XP sp3
Notepad++ DLL Hijacking Vulnerability
The vulnerability allows attackers to execute arbitrary code by tricking a user into opening a specially crafted DLL file from a network share location using Notepad++ 5.8.2. The exploit code presented in the text demonstrates the execution of a message box, but it can be modified to execute any arbitrary code.
Mitigation:
Update to a non-vulnerable version of Notepad++