notepad-plus-plus - DLL Hijacking
CVE-2022-32168

7.8HIGH

Key Information:

Vendor
CVE Published:
28 September 2022

What is CVE-2022-32168?

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

Affected Version(s)

notepad-plus-plus v8.3

notepad-plus-plus <= unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mend Vulnerability Research Team (MVR)
.