CVE-2022-32168

HIGH

Notepad++ < 8.4.5 - DLL Hijacking via UxTheme.dll

Title source: llm
STIX 2.1

Description

Notepad++ versions 8.4.1 and before are vulnerable to DLL hijacking where an attacker can replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0068
EPSS Percentile 47.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
notepad-plus-plus/notepad\+\+ 8.3 - 8.4.5
Published Sep 28, 2022
Tracked Since Feb 18, 2026