vendor:
Notepad++
by:
Bogdan Kurinnoy
7.8
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Notepad++
Affected Version From: < 7.7
Affected Version To: < 7.7
Patch Exists: YES
Related CWE: CVE-2019-16294
CPE: a:notepad++:notepad
Other Scripts:
N/A
Platforms Tested: Windows x64
2019
Notepad++ all x64 versions before 7.7. Remote memory corruption via .ml file.
SciLexer.dll in Scintilla in Notepad++ (x64) before 7.7 allows remote code execution or denial of service via Unicode characters in a crafted .ml file.
Mitigation:
Upgrade to Notepad++ version 7.7 or later.