CVE-2023-6401

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Nov 30, 2023
Updated: May 17, 2024
CWE ID 427

Summary

CVE-2023-6401 is a recently disclosed vulnerability in NotePad++ up to version 8.1. This issue affects an unspecified functionality within the bundled dbghelp.exe component. Manipulation of this component can result in an uncontrolled search path, potentially leading to security risks for local users. The vulnerability was assigned the identifier VDB-246421, and while the vendor was notified, no response has been received.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share