Remote Code Execution Vulnerability in Notepad++ from Scintilla Library
CVE-2019-16294

7.8HIGH

Key Information:

Vendor
CVE Published:
14 September 2019

What is CVE-2019-16294?

A vulnerability exists in the SciLexer.dll, part of the Scintilla library used in Notepad++ for x64 versions prior to 7.7. This issue enables remote code execution or denial of service attacks through specially crafted .ml files containing Unicode characters. Malicious actors can exploit this vulnerability to execute arbitrary code on an affected machine or cause the application to become unresponsive, posing a significant risk to users' security and system integrity.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2019-16294 : Remote Code Execution Vulnerability in Notepad++ from Scintilla Library