CVE-2025-49144

HIGH

Notepad++ <8.8.1 - Privilege Escalation

Title source: llm

Description

Notepad++ is a free and open-source source code editor. In versions 8.8.1 and prior, a privilege escalation vulnerability exists in the Notepad++ v8.8.1 installer that allows unprivileged users to gain SYSTEM-level privileges through insecure executable search paths. An attacker could use social engineering or clickjacking to trick users into downloading both the legitimate installer and a malicious executable to the same directory (typically Downloads folder - which is known as Vulnerable directory). Upon running the installer, the attack executes automatically with SYSTEM privileges. This issue has been fixed and will be released in version 8.8.2.

Exploits (10)

nomisec WORKING POC 85 stars
by TheTorjanCaptain · poc
https://github.com/TheTorjanCaptain/CVE-2025-49144_PoC
nomisec WORKING POC 8 stars
by b0ySie7e · poc
https://github.com/b0ySie7e/Notepad-8.8.1_CVE-2025-49144
github WORKING POC 2 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2025/CVE-2025-49144
nomisec SUSPICIOUS 1 stars
by ammarm0010 · poc
https://github.com/ammarm0010/CVE-2025-49144_PoC
nomisec WORKING POC 1 stars
by Vr00mm · poc
https://github.com/Vr00mm/CVE-2025-49144
nomisec WRITEUP
by assad12341 · poc
https://github.com/assad12341/notepad-v8.8.1-LPE-CVE-
nomisec WORKING POC
by timsonner · poc
https://github.com/timsonner/CVE-2025-49144-Research
nomisec WORKING POC
by 0xCZR1 · poc
https://github.com/0xCZR1/cve-2025-49144
github WORKING POC
by havertz2110 · cpoc
https://github.com/havertz2110/CVE-2025-49144
nomisec STUB
by onniio · poc
https://github.com/onniio/CVE-2025-49144

Scores

CVSS v3 7.3
EPSS 0.0004
EPSS Percentile 13.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-276 CWE-427 CWE-272
Status draft

Timeline

Published Jun 23, 2025
Tracked Since Feb 18, 2026