QID 378065

Date Published: 2023-03-15

QID 378065: NotePad++ "UxTheme.dll" DLL Hijacking Vulnerability (CVE-2022-32168)

Notepad++ is a text editor and source code editor for Windows.

UxTheme.dll in Notepad++ before 8.4.1 allows an attacker to replace the vulnerable dll (UxTheme.dll) with his own dll and run arbitrary code in the context of Notepad++.

Affected Versions:
Notepad++ version prior to 8.4.1 are affected.

QID Detection Logic(Authenticated):
This QID checks for vulnerable version of NotePad ++ by checking the exe file.

Successful exploitation of the vulnerability may lead to replace the original DLL file with fake DLL file containing malicious code.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Customers are advised to upgrade to Notepad++ version 8.4.1 For more information, click here.

    CVEs related to QID 378065

    Software Advisories
    Advisory ID Software Component Link
    Notepad Plus Plus Notepad Plus Plus URL Logo notepad-plus-plus.org/