logo

CVE-2026-20841: Arbitrary Code Execution in the Windows Notepad

ID: 4e094321-f1c9-571c-bd75-1fcfc2a1cf66

STIX ID: report--4e094321-f1c9-571c-bd75-1fcfc2a1cf66

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
65/100

Date Published: 2026-02-19

Date Updated: 2026-05-01

Author: TrendAI Research Team

...
...

A remote code execution vulnerability was identified in Windows Notepad's Markdown rendering: insufficient link filtering allows crafted protocol URIs to be forwarded to ShellExecuteExW, enabling arbitrary command execution if a user opens a malicious .md file and clicks a link. The flaw arises from fixed extension detection and inadequate sanitization of link values; .md files are not registered to Notepad by default but are rendered when opened manually.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.