- Description
- Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.
- Source
- vulnerabilitylab@mend.io
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- vulnerabilitylab@mend.io
- CWE-427
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:notepad-plus-plus:notepad\\+\\+:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC679137-8D40-4D8B-B833-A3F8DFD55840",
"versionEndExcluding": "8.4.5",
"versionStartIncluding": "8.3"
}
],
"operator": "OR"
}
]
}
]