CVE-2025-56383
Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users.
- Affected products
- Notepad++
- Fix
- Available
- CVSS 3.1
- 8.4 HIGH
- EPSS
- 0.4% (31th percentile)
- Weakness
- CWE-427
- NVD status
- Deferred
- Published
- 2025-09-26
CVE-2025-56383 at NVD
2 known exploits for CVE-2025-56383
Proof-of-concept code and exploit modules indexed by Sploitus