PT-2019-3959 · Notepad++ · Notepad++

CVE-2019-16294

·

Publicado

2019-09-14

·

Atualizado

2024-03-11

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 7.7
Description The issue is related to insufficient input validation in the SciLexer.dll component of the Scintilla text editing component in Notepad++. This can be exploited by a remote attacker using a specially crafted .ml file containing Unicode characters, potentially leading to remote code execution or denial of service.
Recommendations For versions prior to 7.7, update to version 7.7 or later to resolve the issue. As a temporary workaround, consider avoiding the use of .ml files containing Unicode characters in Notepad++ until the update is applied.

Exploit

Correção

DoS

RCE

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-04475
CVE-2019-16294

Produtos afetados

Notepad++