PT-2022-21130 · Microsoft · Uxtheme.Dll

Published

2022-09-28

·

Updated

2022-09-29

·

CVE-2022-32168

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notepad++ versions 8.4.1 and before
Description The issue allows an attacker to replace the vulnerable dll (UxTheme.dll) with their own dll, enabling them to run arbitrary code in the context of Notepad++. This is a result of DLL hijacking.
Recommendations For Notepad++ versions 8.4.1 and before, consider updating to a version that is not affected by this issue. As a temporary workaround, restrict access to the vulnerable dll (UxTheme.dll) to minimize the risk of exploitation.

Exploit

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2022-32168

Affected Products

Uxtheme.Dll