๐Ÿ” CVE Alert

CVE-2025-49144

HIGH 7.3

Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2.

CWE CWE-272 CWE-276 CWE-427
Vendor notepad-plus-plus
Product notepad-plus-plus
Published Jun 23, 2025
Last Updated Feb 26, 2026
Stay Ahead of the Next One

Get instant alerts for notepad-plus-plus notepad-plus-plus

Be the first to know when new high vulnerabilities affecting notepad-plus-plus notepad-plus-plus are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

notepad-plus-plus / notepad-plus-plus
< 8.8.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-9vx8-v79m-6m24 github.com: https://github.com/notepad-plus-plus/notepad-plus-plus/commit/f2346ea00d5b4d907ed39d8726b38d77c8198f30 drive.google.com: https://drive.google.com/drive/folders/11yeUSWgqHvt4Bz5jO3ilRRfcpQZ6Gvpn vicarius.io: https://www.vicarius.io/vsociety/posts/cve-2025-49144-detect-notepad-vulnerability vicarius.io: https://www.vicarius.io/vsociety/posts/cve-2025-49144-mitigate-notepad-vulnerability vicarius.io: https://www.vicarius.io/vsociety/posts/cve-2025-49144-detect-notepad-vulnerability-1 vicarius.io: https://www.vicarius.io/vsociety/posts/cve-2025-49144-mitigate-notepad-vulnerability-1