High-Severity Vulnerability in Notepad++

5 hours ago 1

Background

Notepad++ has released security updates addressing a vulnerability (CVE-2025-49144) affecting their product. The proof-of-concept exploit targeting this vulnerability is publicly available.

Impact

Successful exploitation of the vulnerability could allow an attacker with low privilege access to perform privilege escalation by executing a maliciously crafted file with system-level privileges, potentially gaining full control of the affected system.

Affected Products

The vulnerability affects Notepad++ versions 8.8.1 and earlier.

Mitigation

Users and administrators of affected products are advised to update to the latest version.

References

https://nvd.nist.gov/vuln/detail/CVE-2025-49144

https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-9vx8-v79m-6m24

https://cybersecuritynews.com/notepad-vulnerability/

Read Entire Article