ZeroHour

CVE-2022-32168

PoC
CVSS 3.1
7.8 high
EPSS
<1%p52
Published
()
Modified
Description

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

Vendors
notepad-plus-plus
Products
notepad\+\+
Weakness
CWE-427
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.