CVE-2023-6401
A vulnerability classified as problematic was found in NotePad++ up to 8.1. Affected by this vulnerability is an unknown functionality of the file dbghelp.exe. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The identifier VDB-246421 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
- Affected products
- Notepad++
- Notepad-plus-plus Notepad\+\+
- ≤ 8.1
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.3% (26th percentile)
- Weakness
- CWE-427
- NVD status
- Modified
- Published
- 2023-11-30
CVE-2023-6401 at NVD
2 known exploits for CVE-2023-6401
Proof-of-concept code and exploit modules indexed by Sploitus