Notepad++ Vulnerability Lets Attackers Take Full System Control; PoC Released

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
951
3,490
2,168
Germany
A vulnerability in Notepad++ could let attackers gain SYSTEM-level privileges through a simple local exploit.
Critical installer bug leaves systems exposed
A newly identified vulnerability in version 8.8.1 of Notepad++ , the popular text and source code editor, has sparked concern among security professionals.
The flaw, tracked as CVE-2025-49144, could let attackers seize full control of affected Windows systems, if left unpatched. It stems from a misconfigured executable search path in the application’s installer, which can be exploited to escalate privileges to SYSTEM level.
Continue reading:
 
In response to the disclosure of the vulnerability, Notepad++ developers have released version 8.8.2, which addresses the flaw by strengthening executable loading practices and enforcing secure path resolution.
The release isn't yet available on the official website or via the "Update Notepad++" command as of now.
 
  • Like
Reactions: simmerskool
The release isn't yet available on the official website or via the "Update Notepad++" command as of now.
He has issues with the certificate...
Notepad++ v8.8.2 Release Candidate

Please note that the 8.8.2 RC binaries are not signed due to the expiration of Notepad++ code signing certificate issued by DigiCert.
As a result, the updater for both plugins & Notepad++ itself will not function - I will adjust the security mechanism to restore the functionality, and will post 8.8.2 RC2 here ASAP.
Edit: the security mechanism has been switched from the certificate check to SHA256 check. The updater & plugin manager will work in 8.8.2 RC2
In order to renew the code signing certificate, I also have to renew the trademark (which, unfortunately, has expired as well). The trademark is currently under examination and listed as pending. I’ve contacted DigiCert validation team to ask whether it’s possible to issue the certificate to “Notepad++” while the trademark is still pending.
However, since they also require Notepad++ to be a recognized business entity, we’ll most likely proceed without code signing - at least for this version. :(
Edit: An announcement has been made to notify users about the situation of upcoming release, and to ask for help in obtaining a certificate:
v8.8.2 available in 1 week, without certificate | Notepad++