vendor:
Notepad3
by:
Ihsan Sencan
7.5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: Notepad3
Affected Version From: 1.0.2.350
Affected Version To: 1.0.2.350
Patch Exists: NO
Related CWE: N/A
CPE: a:rizonesoft:notepad3:1.0.2.350
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WiN7_x64/KaLiLinuX_x64
2018
Notepad3 1.0.2.350 – Denial of Service (PoC)
Notepad3 is vulnerable to a denial of service attack when a maliciously crafted file is opened. When the user attempts to open the file, Notepad3 will crash due to a buffer overflow. The exploit is triggered when the user attempts to encrypt the file using a passphrase. The malicious file contains a 256 byte buffer of 'A' characters, which causes the application to crash.
Mitigation:
Users should avoid opening files from untrusted sources and should ensure that all software is up to date.