PT-2023-4643 · Notepad++ · Notepad++

Jaroslav Lobačevski

·

Publicado

2023-08-21

·

Atualizado

2025-08-19

·

CVE-2023-40031

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notepad++ versions 8.5.6 and prior
Description The issue is related to a heap buffer write overflow in the Utf8 16 Read::convert function, which may lead to arbitrary code execution when a user opens a specially crafted file. This can potentially allow an attacker to execute arbitrary code.
Recommendations For versions 8.5.6 and prior, update to version 8.5.7 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the Utf8 16 Read::convert function until a patch is available. Restrict access to potentially vulnerable files to minimize the risk of exploitation.

Exploit

Correção

Buffer Overflow

Heap Based Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-05051
BDU:2023-05226
CVE-2023-40031

Produtos afetados

Notepad++