Improper Verification of Cryptographic Signature in Notepad++ - #VU144994
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to execute modified code through the trusted updater launch path.
The vulnerability exists due to improper verification of cryptographic signature in the updater signature verification path when launching updater-related binaries from the GUI updater path. A local user can place or replace a modified updater-related binary that retains certificate metadata but has an invalid Authenticode digest to execute modified code through the trusted updater launch path.
User interaction is required to trigger the updater path from the GUI.