PT-2026-8315 · Flos+1 · Notepad2+1

Cyber-Wo0Dy

·

Published

2026-02-16

·

Updated

2026-02-21

·

CVE-2026-2538

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flos Freeware Notepad2 versions 4.2.22 through 4.2.25
Description A security flaw exists in Flos Freeware Notepad2. The issue involves an uncontrolled search path within an unknown function in the Msimg32.dll library. Local access is required for exploitation, and the exploitability is considered difficult.
Recommendations Update Flos Freeware Notepad2 to a version newer than 4.2.25.

Fix

Untrusted Search Path

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2026-2538

Affected Products

Msimg32.Dll
Notepad2