CVE-2017-8803
Notepad++ 7.3.3 (32-bit) with Hex Editor Plugin v0.9.5 might allow user-assisted attackers to execute code via a crafted file, because of a "Data from Faulting Address controls Code Flow" issue. One threat model is a victim who obtains an untrusted crafted file from a remote location and issues several user-defined commands.
- Affected products
- Notepad++
- Mh-nexus Hex Editor
- = 0.9.5
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 1.6% (74th percentile)
- Weakness
- CWE-119
- NVD status
- Modified
- Published
- 2017-07-05
CVE-2017-8803 at NVD
No indexed exploits for CVE-2017-8803 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2017-8803 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.