Skip to content
Threat Feed
high advisory

Multiple Vulnerabilities in Notepad++

Notepad++ contains multiple vulnerabilities that an attacker can exploit to bypass security controls, steal authentication credentials, manipulate files, execute arbitrary code, or trigger denial-of-service.

The BSI has released an advisory regarding multiple vulnerabilities within the Notepad++ application. These vulnerabilities allow an unauthenticated attacker to impact the confidentiality, integrity, and availability of the host system. By exploiting these flaws, an attacker may bypass existing security controls, steal Windows authentication credentials, perform unauthorized file operations such as deletion or modification, or achieve arbitrary code execution. Additionally, the flaws can be leveraged to cause denial-of-service conditions. These vulnerabilities pose a significant risk to workstations where Notepad++ is deployed, particularly if the application is used to open untrusted files from external sources.

Impact

Successful exploitation could lead to full system compromise, loss of sensitive authentication data, and persistent damage to local files. Given the widespread use of Notepad++ in enterprise environments, these vulnerabilities represent a high risk for lateral movement and local privilege escalation. There are no currently reported victim numbers or specific sector targets, but all Windows environments utilizing Notepad++ are considered potentially affected.

Recommendation

  • Monitor vendor communication channels for forthcoming security patches for the Notepad++ application.
  • Evaluate the necessity of Notepad++ on high-security endpoints and restrict file-opening capabilities for untrusted or unknown file types.
  • Implement application whitelisting or integrity monitoring to identify unauthorized modification of application files or suspicious child processes spawned by notepad++.exe.

Immediate actions

Review inventory of Notepad++ installations and prepare for scheduled patching.

IT Operations 72h

Mitigations

Patch Notepad++ once updates are released by the vendor.

medium_term IT Operations

All instances of Notepad++