CVE-2023-6401
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Nov 30, 2023
Updated: May 17, 2024
CWE ID 427
Summary
CVE-2023-6401 is a recently disclosed vulnerability in NotePad++ up to version 8.1. This issue affects an unspecified functionality within the bundled dbghelp.exe component. Manipulation of this component can result in an uncontrolled search path, potentially leading to security risks for local users. The vulnerability was assigned the identifier VDB-246421, and while the vendor was notified, no response has been received.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Notepad Plus Plus Notepad++