CVE-2026-38972
גבוהה 7.8
תיאור (מקור, אנגלית)
Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application calls LoadLibrary(L"MSFTEDIT.DLL") with a bare DLL name, which allows a local attacker to place a malicious MSFTEDIT.DLL in the application directory or another preferred DLL search location and achieve arbitrary code execution in the context of the user when the About dialog is opened.
מדדים
- CVSS 3.1
-
7.8 (HIGH)
מקור הציון: CNA
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-15/8/2026
- CWE
- CWE-427
מוצרים מושפעים
rizonesoft: notepad3
קישורים
- https://github.com/rizonesoft/Notepad3/pull/5606 Issue TrackingPatch
- https://github.com/rizonesoft/Notepad3/issues/5605 ExploitIssue Tracking
- https://github.com/rizonesoft/Notepad3/issues/5605 ExploitIssue Tracking
- https://github.com/rizonesoft/Notepad3 Product