Home

Description

Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users.

PUBLISHED Reserved 2025-08-16 | Published 2025-09-26 | Updated 2025-10-01 | Assigner mitre

References

github.com/notepad-plus-plus/notepad-plus-plus

github.com/zer0t0/CVE-2025-56383-Proof-of-Concept

github.com/zer0t0/CVE-2025-56383-Proof-of-Concept/issues/1

cve.org (CVE-2025-56383)

nvd.nist.gov (CVE-2025-56383)

Download JSON