Notepad++ Security Update Patches Buffer Overflow and Updater Code Execution Flaws
ID: ad7f6ac6-a712-57a0-82d3-0fd70739548b
STIX ID: report--ad7f6ac6-a712-57a0-82d3-0fd70739548b
Feed Name: Cyber Press
Threat Score
Notepad++ v8.9.7 fixes five security vulnerabilities — notably a stack buffer overflow and a Zip Slip path-traversal in the WinGUp auto-updater — that could allow memory corruption, arbitrary code execution, path traversal to write/read arbitrary files, and installer-time command injection. Given the updater-related issues, organizations should prioritize manual patching, especially where the editor runs with elevated privileges or handles sensitive configuration files.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
