Improper Verification of Cryptographic Signature in Notepad++ - #VU144994

 

Improper Verification of Cryptographic Signature in Notepad++ - #VU144994

Published: August 24, 2026


Vulnerability identifier: #VU144994
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute modified code through the trusted updater launch path.

The vulnerability exists due to improper verification of cryptographic signature in the updater signature verification path when launching updater-related binaries from the GUI updater path. A local user can place or replace a modified updater-related binary that retains certificate metadata but has an invalid Authenticode digest to execute modified code through the trusted updater launch path.

User interaction is required to trigger the updater path from the GUI.


Affected software

Notepad++

Remediation

Install security update from vendor's website.

Notepad++ - update to 8.9.8

External References

Related Security Bulletins