PT-2026-55312 · Notepad3 · Notepad3

·

CVE-2026-38972

·

Published

2026-07-02

·

Updated

2026-07-08

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notepad3 versions prior to 6.25.822.2
Description A DLL search-order hijacking issue exists in the About-dialog code path within src/Notepad3.c. The application uses the LoadLibrary() function to load MSFTEDIT.DLL using a bare name. This allows a local attacker to place a malicious version of the DLL in the application directory or other search locations, leading to arbitrary code execution in the user context when the About dialog is opened.
Recommendations Update Notepad3 to a version newer than 6.25.822.1.

Exploit

Fix

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-38972

Affected Products

Notepad3