Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Jun 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 23 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2. | |
Title | Notepad++ Privilege Escalation in Installer via Uncontrolled Executable Search Path | |
Weaknesses | CWE-272 CWE-276 CWE-427 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-23T19:01:16.276Z
Updated: 2025-07-01T03:55:56.212Z
Reserved: 2025-06-02T10:39:41.634Z
Link: CVE-2025-49144

Updated: 2025-06-23T19:23:25.242Z

Status : Awaiting Analysis
Published: 2025-06-23T19:15:23.727
Modified: 2025-06-23T20:16:21.633
Link: CVE-2025-49144

No data.