Missing Authorization in Notepad++ - #VU151935
Published: September 24, 2026
Vulnerability details
The vulnerability allows a local user to modify arbitrary files with elevated privileges.
The vulnerability exists due to missing authorization in the wWinMain UAC command-line operation dispatch when processing #UAC-SAVE# and related command-line arguments. A local user can invoke Notepad++ with crafted UAC operation arguments and approve the UAC prompt to modify arbitrary files with elevated privileges.
The UAC prompt does not display the destination path.